What does preparation for ISO 27001 involve?

Cybersecurity
August 7, 2026

ISO 27001 certification does not start with writing policies and does not end with an external audit. When management asks what ISO 27001 training involves, the correct answer is: building a working information security management system that can be demonstrated with real processes, responsibilities and records. For small and medium-sized companies, this is an opportunity to bring control to access, data, suppliers and incident response, not just an administrative requirement.

What ISO 27001 training involves in practice

ISO/IEC 27001:2022 sets requirements for an Information Security Management System, known as an ISMS. The standard does not prescribe the same technical environment for all organizations. It requires the company to understand its risks, select adequate control measures and manage these measures consistently.

This distinction is essential. A company with 25 employees that processes customer contracts in a cloud platform does not need the same scope and controls as a financial organization with multiple internal systems. In both cases, however, it should be clear who has access to the information, how the data is protected, how to respond to a problem, and how management monitors the results.

Defining the scope and business context

The first real task is to define the scope of the system. It describes which activities, locations, employees, information assets, applications, and suppliers fall under the ISMS. Unclear scope is a common reason for a project to expand unchecked or leave critical processes outside of management.

The scope should not be chosen solely for the purpose of easier auditing. For example, if the sales system is outside the ISMS but processes customer data and contracts through it, this limitation will be difficult to defend. A more sensible approach is to start with a clearly defined business function and its technology environment, and then expand control in a planned manner.

At this stage, stakeholders are also identified: customers, employees, partners, regulators and key suppliers. Contractual requirements, GDPR obligations, NIS2 requirements, if applicable, and internal business continuity objectives are considered.

Roles, commitment and measurable responsibility

ISO 27001 requires management to take responsibility for the system. This does not mean that the manager approves every user access or maintains a register of assets. It means defining priorities, resources, process owners and clear rules for decision-making.

Preparation includes appointing an information security officer, asset owners and risk managers. In a small company, one person can fulfill several roles, as long as they have the competence and authority. It is important that responsibilities do not remain only in documents - in the event of an incident, a change in the system or the departure of an employee, it must be clear who acts and by what deadline.

Risk Assessment - the basis of decisions

Risk assessment is the core of ISO 27001 preparation. It links real business threats to specific protective measures. Instead of a general statement that “cyber attacks are a risk”, the organization analyzes what could happen to a specific asset, what the probability is, and what the effect would be on work, finances, contracts, and reputation.

Assets are not just servers and laptops. They include customer data, contracts, email, cloud accounts, network equipment, backups, key employee knowledge, and critical business processes. Threats such as phishing, misconfiguration, unauthorized access, supplier outage, lost device, or human error are then considered.

For each significant risk, a treatment approach is determined: mitigation through control measures, transfer through contract or insurance, avoidance of the activity, or acceptance of the residual risk. Acceptance is only permissible if informed and approved by the appropriate level in the organization. It is not enough for a risk to simply remain in a table without an owner and a deadline.

Applicability of controls and Risk Treatment Plan

The standard contains a set of controls in Annex A. They cover organizational, technical, physical and people-related measures. Preparation requires the preparation of a Declaration of Applicability, which states which controls are applicable, how they are applied and why certain controls are not relevant.

This is where the difference between a formal and a mature implementation becomes apparent. Not every organization needs to have its own security monitoring center. But if access to cloud mail is not protected by multi-factor authentication, there is no management of administrator accounts and no review of logs, the risk is real regardless of the size of the company.

The treatment plan translates analysis into action. It can include the implementation of MFA, centralized device management, network segmentation, encryption no, backup policies, recovery tests, rights reviews, and employee training. Each task should have a deadline, owner, required resource, and completion criteria.

Policies, procedures, and evidence of performance

Documentation is necessary, but it should not be an end in itself. An information security policy provides direction. Procedures describe how specific things are done: hiring and firing employees, granting and revoking access, managing changes, incident response, working with vendors, and recovering from outages.

An auditor will not appreciate a highly detailed access management procedure if the company cannot show actual records of approvals, periodic reviews, and timely account closures. Therefore, preparation includes creating working evidence: asset and risk registers, training protocols, backup reports, incident records, test results, and vendor reviews.

External vendors deserve special attention. A cloud provider, payroll company, telecom operator, or external IT partner often processes or maintains critical information. The company needs to know what services it receives, what the contractual support levels are, how it is notified in the event of an incident, and what happens to the data when the service is terminated.

Technical and operational measures that are often missing

In many organizations, good intentions do not extend to day-to-day IT work. The policy says that data is kept, but backups are not tested. A strong password is required, but there is no MFA. Employees undergo training, but phishing simulations and reporting rules are missing.

Hands-on training checks whether basic controls are working: system updates, antivirus or EDR protection, protected administrator access, device inventory, monitoring, archiving, and an incident response plan. In hybrid work, personal devices, home networks, access to SaaS applications, and file sharing outside of approved channels should also be assessed.

Not every control needs to be implemented at the same time. If the organization has limited resources, the risks with the greatest potential impact are addressed first: compromised email, lack of recoverable backups, excessive administrator rights, and unmanaged devices.

Internal audit, management review, and certification audit

Before the external audit, the system must be checked internally. The internal audit assesses whether the requirements of ISO 27001, internal policies, and planned controls are being followed. It must be sufficiently independent - one should not audit one’s own work without additional verification.

Findings are recorded, analyzed, and corrected. This is followed by a management review, which looks at the risks, incidents, audit results, achievement of objectives, changes in the environment, and needed improvements. This is the point at which the system is linked to business management, and is not left solely to the IT department.

A certification audit typically has two stages. The first reviews readiness, scope, and underlying documentation. The second checks practical implementation and evidence. Certification does not mean that incidents will not occur. It shows that the organization has a mechanism in place to manage risks, respond, and improve its system.

Preparing for ISO 27001 is most useful when it becomes a normal way of working: accesses are reviewed in a timely manner, backups are tested, suppliers are managed, and issues are reported without delay. Then certification is the result of a controllable IT environment, not a short-term project before an audit.


Tags:
#ISO 27001 preparation#ISMS implementation#ISO 27001 certification#information security standard#ISO 27001 for business
Share this article:

Get in touch

Related Articles

All posts