Guide
Getting started with ISO 27001 in 30 days
A concrete, week-by-week plan to lay the foundations of an ISO 27001:2022-compliant ISMS.
Week 1 — Scope it
- Define the scope (business units, sites, systems)
- Appoint an ISMS lead and an executive sponsor
- Identify stakeholders and their expectations
Week 2 — Map it out
- Asset inventory (information, software, hardware, people)
- Data flow mapping
- Identification of legal and contractual requirements
Week 3 — Assess the risks
- Assessment methodology (e.g. EBIOS RM or simplified ISO 27005)
- Initial risk register (top 20)
- Draft treatment plan
Week 4 — Declare and plan
- Information security policy signed by management
- Statement of Applicability (SoA) v1
- 6-month roadmap to the certification audit
Use this resource in BeeLink
Create your organization and import this template into your compliance workspace in one click.
Create an accountIn the same category
nFADP: what really changes
The 12 structural changes between the old FADP (1992) and the new Act (2023).
FINMA Circ. 2023/1 for non-lawyers
A plain-language breakdown of the operational risks and resilience circular.
DORA: mapping your ICT third parties
The register to produce, criticality criteria, and contractual requirements.