Guide

Getting started with ISO 27001 in 30 days

A concrete, week-by-week plan to lay the foundations of an ISO 27001:2022-compliant ISMS.

Week 1 — Scope it

  • Define the scope (business units, sites, systems)
  • Appoint an ISMS lead and an executive sponsor
  • Identify stakeholders and their expectations

Week 2 — Map it out

  • Asset inventory (information, software, hardware, people)
  • Data flow mapping
  • Identification of legal and contractual requirements

Week 3 — Assess the risks

  • Assessment methodology (e.g. EBIOS RM or simplified ISO 27005)
  • Initial risk register (top 20)
  • Draft treatment plan

Week 4 — Declare and plan

  • Information security policy signed by management
  • Statement of Applicability (SoA) v1
  • 6-month roadmap to the certification audit

Use this resource in BeeLink

Create your organization and import this template into your compliance workspace in one click.

Create an account