Runbook 01 β ISO/IEC 27001 Implementation & Certification Readiness
Runbook Information
Section titled βRunbook Informationβ| Item | Details |
|---|---|
| Runbook | 01 β ISO/IEC 27001 Implementation & Certification Readiness |
| Module | ISO/IEC 27001 |
| Difficulty | Advanced |
| Estimated Time | Multi-Week Enterprise Workflow |
| Primary Role | GRC Analyst / ISMS Manager |
| Supporting Roles | CISO, Risk Owners, Control Owners, Internal Audit, Legal, HR, IT, Security, Engineering |
| Primary Output | Certification-Ready ISMS |
| Runbook Type | ISO/IEC 27001 Implementation & Assurance |
Purpose
Section titled βPurposeβThis runbook provides a repeatable procedure for taking an organization from the initial decision to implement ISO/IEC 27001 through certification readiness.
The process covers:
ISO Initiative βContext βScope βGovernance βGap Assessment βRisk Assessment βRisk Treatment βStatement of Applicability βControl Implementation βEvidence βInternal Audit βManagement Review βCorrective Action βStage 1 Readiness βStage 2 Readiness βCertification βSurveillanceThe objective is not merely to create documentation.
The objective is to build an ISMS that can demonstrate:
-
Clear business alignment.
-
Defined accountability.
-
Consistent risk management.
-
Appropriate control selection.
-
Operating security controls.
-
Reliable evidence.
-
Independent assurance.
-
Leadership oversight.
-
Continual improvement.
Runbook Success Outcome
Section titled βRunbook Success OutcomeβThe organization should be able to answer:
What is in our ISMS?
Why is it in scope?
What are our major risks?
How are those risks treated?
Which controls are applicable?
Who owns each control?
Is each control operating?
What evidence proves it?
What did internal audit find?
What has management reviewed?
What corrective actions remain?
Are we ready for certification?Phase 1 β Initiate the ISO Program
Section titled βPhase 1 β Initiate the ISO ProgramβStep 1 β Confirm the Business Driver
Section titled βStep 1 β Confirm the Business DriverβDocument why the organization is implementing ISO/IEC 27001.
Common drivers include:
-
Customer requirement.
-
Enterprise sales.
-
Security maturity.
-
Regulatory expectations.
-
Contractual commitments.
-
Market expansion.
-
Supplier assurance.
-
Internal governance improvement.
Example:
Business Driver:Enterprise customers increasingly requireindependent information-security assurance.Avoid beginning the program with:
We need the certificate.
Instead ask:
What business objective will the ISMS support?
Step 2 β Confirm Executive Sponsorship
Section titled βStep 2 β Confirm Executive SponsorshipβIdentify an executive sponsor.
Example:
Executive Sponsor:CISO
Executive Oversight:Risk CommitteeThe sponsor should have sufficient authority to:
-
Allocate resources.
-
Resolve disputes.
-
Escalate risk.
-
Approve direction.
-
Support cross-functional participation.
Step 3 β Appoint ISMS Leadership
Section titled βStep 3 β Appoint ISMS LeadershipβIdentify:
ISMS Owner
ISMS Manager
GRC Lead
Executive SponsorRecord clear responsibilities.
Step 4 β Establish Project Governance
Section titled βStep 4 β Establish Project GovernanceβCreate a project governance structure.
Example:
Executive Sponsor βISMS Steering Committee βISMS Manager βGRC βWorkstream OwnersCreate a governance calendar.
Phase 2 β Understand Organizational Context
Section titled βPhase 2 β Understand Organizational ContextβStep 5 β Identify Internal Issues
Section titled βStep 5 β Identify Internal IssuesβFacilitate a context workshop.
Consider:
-
Business strategy.
-
Organizational growth.
-
Technology architecture.
-
Security maturity.
-
Staffing.
-
Legacy systems.
-
Cloud adoption.
-
Remote workforce.
-
Acquisitions.
-
Organizational dependencies.
Record each relevant issue.
Example:
Issue:Rapid cloud adoption
Potential Impact:Increased configuration and identity riskStep 6 β Identify External Issues
Section titled βStep 6 β Identify External IssuesβConsider:
-
Threat landscape.
-
Regulatory changes.
-
Customer expectations.
-
Supply-chain risk.
-
Technology changes.
-
Market requirements.
-
Geopolitical factors.
Example:
Issue:Increasing ransomware attacks
ISMS Impact:Improve recovery assurance and privileged accessStep 7 β Build the Context Register
Section titled βStep 7 β Build the Context RegisterβUse:
| Field | Example |
|---|---|
| ID | CTX-001 |
| Issue | Rapid cloud adoption |
| Type | Internal |
| Security Impact | Cloud governance risk |
| Owner | CIO |
| Review | Quarterly |
Step 8 β Establish Context Review
Section titled βStep 8 β Establish Context ReviewβDefine:
Owner:GRC
Review:Quarterly / Event DrivenTriggers may include:
-
Major incidents.
-
Acquisitions.
-
New products.
-
New regulations.
-
New locations.
-
New critical vendors.
Phase 3 β Identify Interested Parties & Requirements
Section titled βPhase 3 β Identify Interested Parties & RequirementsβStep 9 β Identify Interested Parties
Section titled βStep 9 β Identify Interested PartiesβTypical parties include:
Customers
Employees
Regulators
Suppliers
Partners
Executive Management
Shareholders
Certification BodyStep 10 β Capture Requirements
Section titled βStep 10 β Capture RequirementsβFor each party, determine relevant information-security requirements.
Example:
Interested Party:Enterprise Customer
Requirement:Protect confidential customer informationand notify material security incidents.Step 11 β Build Requirements Register
Section titled βStep 11 β Build Requirements RegisterβUse:
| ID | Requirement | Source | Owner | ISMS Impact |
|---|---|---|---|---|
| REQ-001 | Encrypt customer data | Contract | Security | Encryption |
| REQ-002 | Annual vendor review | Policy | GRC | TPRM |
| REQ-003 | Incident notification | Regulation | Legal | IR |
Step 12 β Assign Requirement Owners
Section titled βStep 12 β Assign Requirement OwnersβExamples:
Legalβ Regulatory requirements
GRCβ Security framework requirements
Procurementβ Supplier contractual requirements
Sales / Legalβ Customer security commitmentsPhase 4 β Define ISMS Scope
Section titled βPhase 4 β Define ISMS ScopeβStep 13 β Identify Critical Business Services
Section titled βStep 13 β Identify Critical Business ServicesβStart with business services rather than systems.
Example:
Critical Service:Enterprise SaaS PlatformThen map supporting:
Applications
Infrastructure
Identity
Data
People
Processes
SuppliersStep 14 β Map Dependencies
Section titled βStep 14 β Map DependenciesβCreate:
Business Service βApplication βCloud Platform βIdentity βDatabase βThird PartiesIdentify:
-
Upstream dependencies.
-
Downstream dependencies.
-
Shared services.
-
Out-of-scope interfaces.
Step 15 β Define Boundaries
Section titled βStep 15 β Define BoundariesβDocument:
Products
Services
Business Units
Locations
Personnel
Technology
Supporting ProcessesStep 16 β Evaluate Exclusions
Section titled βStep 16 β Evaluate ExclusionsβAsk:
-
Is the exclusion genuinely outside the ISMS?
-
Does it support an in-scope service?
-
Does it introduce an interface?
-
Can exclusion create unmanaged risk?
Do not exclude components merely to reduce audit effort.
Step 17 β Draft Scope Statement
Section titled βStep 17 β Draft Scope StatementβExample:
The ISMS covers the design, development, operation, maintenance, and support of the organizationβs enterprise SaaS platform and supporting production cloud infrastructure, identity services, security operations, engineering processes, and personnel supporting those services.
Step 18 β Obtain Scope Approval
Section titled βStep 18 β Obtain Scope ApprovalβRecord:
Scope Owner
Version
Approval
Effective DatePhase 5 β Establish ISMS Governance
Section titled βPhase 5 β Establish ISMS GovernanceβStep 19 β Define Roles
Section titled βStep 19 β Define RolesβIdentify:
-
Executive Sponsor.
-
CISO.
-
ISMS Manager.
-
GRC.
-
Risk Owners.
-
Control Owners.
-
Process Owners.
-
Internal Audit.
Step 20 β Build the RACI
Section titled βStep 20 β Build the RACIβInclude:
Scope
Policy
Risk Assessment
Risk Treatment
SoA
Control Operation
Internal Audit
Management Review
Corrective ActionStep 21 β Define Risk Authority
Section titled βStep 21 β Define Risk AuthorityβExample:
| Residual Risk | Approval |
|---|---|
| Low | Manager |
| Moderate | Director |
| High | CISO |
| Critical | Executive Risk Committee |
Step 22 β Establish Steering Committee
Section titled βStep 22 β Establish Steering CommitteeβTypical participants:
CISO
GRC
IT
Engineering
Legal
HR
Procurement
Business LeadershipStep 23 β Create Governance Calendar
Section titled βStep 23 β Create Governance CalendarβTrack:
-
Risk review.
-
Policy review.
-
Control review.
-
Internal audit.
-
Management review.
-
Certification activities.
Phase 6 β Perform Initial ISO Gap Assessment
Section titled βPhase 6 β Perform Initial ISO Gap AssessmentβStep 24 β Build Clause-Level Checklist
Section titled βStep 24 β Build Clause-Level ChecklistβAssess Clauses 4β10.
For each requirement record:
Requirement
Current State
Evidence
Status
Gap
Action
Owner
TargetUse statuses:
Conformant
Partially Conformant
Nonconformant
Not AssessedStep 25 β Assess Annex A Readiness
Section titled βStep 25 β Assess Annex A ReadinessβReview the relevant control environment.
Do not immediately build a final SoA.
At this stage identify:
-
Existing controls.
-
Missing controls.
-
Unclear ownership.
-
Missing evidence.
-
Process weaknesses.
Step 26 β Create Gap Register
Section titled βStep 26 β Create Gap RegisterβExample:
| Gap | Area | Severity | Owner | Target |
|---|---|---|---|---|
| GAP-001 | Internal Audit | High | GRC | Oct |
| GAP-002 | Vendor Reviews | High | TPRM | Nov |
| GAP-003 | Document Control | Medium | GRC | Sep |
Step 27 β Prioritize Gaps
Section titled βStep 27 β Prioritize GapsβConsider:
Certification Criticality
Risk
Implementation Time
Dependencies
Resource NeedsPhase 7 β Establish Risk Assessment Methodology
Section titled βPhase 7 β Establish Risk Assessment MethodologyβStep 28 β Define Risk Model
Section titled βStep 28 β Define Risk ModelβDocument:
Likelihood
Impact
Risk Matrix
Risk Ratings
Acceptance Criteria
Risk Ownership
Review FrequencyStep 29 β Define Likelihood
Section titled βStep 29 β Define LikelihoodβExample:
| Score | Rating |
|---|---|
| 1 | Rare |
| 2 | Unlikely |
| 3 | Possible |
| 4 | Likely |
| 5 | Almost Certain |
Step 30 β Define Impact
Section titled βStep 30 β Define ImpactβConsider:
Financial
Operational
Customer
Legal
Regulatory
ReputationalStep 31 β Define Risk Matrix
Section titled βStep 31 β Define Risk MatrixβExample:
Risk Score =Likelihood Γ ImpactDocument rating thresholds.
Step 32 β Define Acceptance Criteria
Section titled βStep 32 β Define Acceptance CriteriaβExample:
Lowβ Acceptable
Moderateβ Owner Review
Highβ Treatment / Senior Approval
Criticalβ Immediate EscalationPhase 8 β Perform Information Security Risk Assessment
Section titled βPhase 8 β Perform Information Security Risk AssessmentβStep 33 β Define Assessment Scope
Section titled βStep 33 β Define Assessment ScopeβAlign with the ISMS scope.
Step 34 β Identify Assets & Services
Section titled βStep 34 β Identify Assets & ServicesβInclude:
Information
Applications
Cloud Platforms
Identity
Endpoints
Processes
People
Third PartiesStep 35 β Identify Threats
Section titled βStep 35 β Identify ThreatsβExamples:
-
External attack.
-
Insider threat.
-
Ransomware.
-
Human error.
-
Cloud failure.
-
Supply-chain compromise.
-
Data leakage.
Step 36 β Identify Vulnerabilities
Section titled βStep 36 β Identify VulnerabilitiesβExamples:
Weak MFA
Excessive Access
Missing Patch
Cloud Misconfiguration
Weak Vendor Governance
Untested RecoveryStep 37 β Develop Risk Statements
Section titled βStep 37 β Develop Risk StatementsβUse:
There is a risk that [threat/event] may exploit [condition], resulting in [business impact].
Step 38 β Assess Inherent Risk
Section titled βStep 38 β Assess Inherent RiskβScore before existing controls.
Step 39 β Identify Existing Controls
Section titled βStep 39 β Identify Existing ControlsβFor each risk record:
Control ID
Control Description
Owner
Evidence
EffectivenessStep 40 β Evaluate Control Effectiveness
Section titled βStep 40 β Evaluate Control EffectivenessβUse:
Effective
Partially Effective
Ineffective
Not TestedStep 41 β Determine Residual Risk
Section titled βStep 41 β Determine Residual RiskβRecalculate risk based on the existing control environment.
Step 42 β Assign Risk Owner
Section titled βStep 42 β Assign Risk OwnerβEvery material risk requires an accountable owner.
Step 43 β Complete Risk Register
Section titled βStep 43 β Complete Risk RegisterβMinimum fields:
Risk ID
Risk Statement
Business Service
Asset
Threat
Vulnerability
Inherent Risk
Controls
Control Effectiveness
Residual Risk
Risk Owner
TreatmentPhase 9 β Develop Risk Treatment Plan
Section titled βPhase 9 β Develop Risk Treatment PlanβStep 44 β Evaluate Risks Against Acceptance Criteria
Section titled βStep 44 β Evaluate Risks Against Acceptance CriteriaβFor each risk decide:
Mitigate
Avoid
Transfer
AcceptStep 45 β Select Controls
Section titled βStep 45 β Select ControlsβConsider:
-
Existing controls.
-
Annex A.
-
Legal requirements.
-
Contractual requirements.
-
Additional internal controls.
Step 46 β Create Treatment Actions
Section titled βStep 46 β Create Treatment ActionsβWeak:
Improve IAM.Strong:
Deploy phishing-resistant MFA for all privileged production accounts.
Step 47 β Assign Treatment Owner
Section titled βStep 47 β Assign Treatment OwnerβDistinguish:
Risk Owner
Treatment Owner
Control OwnerStep 48 β Set Target Dates
Section titled βStep 48 β Set Target DatesβPrioritize based on risk and dependencies.
Step 49 β Define Target Residual Risk
Section titled βStep 49 β Define Target Residual RiskβExample:
Current:High
Target:ModerateStep 50 β Obtain Risk Owner Approval
Section titled βStep 50 β Obtain Risk Owner ApprovalβDocument treatment approval.
Step 51 β Maintain RTP
Section titled βStep 51 β Maintain RTPβInclude:
Risk
Treatment
Control
Owner
Target
Target Residual Risk
Status
EvidencePhase 10 β Build Statement of Applicability
Section titled βPhase 10 β Build Statement of ApplicabilityβStep 52 β Review Annex A
Section titled βStep 52 β Review Annex AβConsider the full Annex A control set.
For each control determine:
Applicable
Not ApplicableStep 53 β Determine Applicability Drivers
Section titled βStep 53 β Determine Applicability DriversβPossible drivers:
Risk
Legal
Regulatory
Contract
Business
Internal PolicyStep 54 β Document Inclusion Justification
Section titled βStep 54 β Document Inclusion JustificationβExample:
Applicable because the organization relies on privileged access to production cloud services, and strong authentication is necessary to treat credential-compromise risk.
Step 55 β Document Exclusion Justification
Section titled βStep 55 β Document Exclusion JustificationβAvoid:
Not needed.Provide specific organizational context.
Step 56 β Identify Inherited Controls
Section titled βStep 56 β Identify Inherited ControlsβExample:
Data Center Physical Securityβ Cloud ProviderDocument provider assurance.
Step 57 β Identify Shared Controls
Section titled βStep 57 β Identify Shared ControlsβExample:
Business Continuity
Provider:Infrastructure resilience
Organization:Application recoveryStep 58 β Record Implementation Status
Section titled βStep 58 β Record Implementation StatusβUse consistent statuses:
Implemented
Partially Implemented
Planned
Not Implemented
Inherited
SharedStep 59 β Assign Control Owners
Section titled βStep 59 β Assign Control OwnersβAvoid generic ownership such as:
ITwhere a specific accountable role exists.
Step 60 β Link Risks
Section titled βStep 60 β Link RisksβMap:
Risk βTreatment βControl βSoAStep 61 β Link Evidence
Section titled βStep 61 β Link EvidenceβReference supporting evidence.
Step 62 β Approve the SoA
Section titled βStep 62 β Approve the SoAβRecord:
-
Owner.
-
Version.
-
Review.
-
Approval.
Phase 11 β Build Enterprise Control Library
Section titled βPhase 11 β Build Enterprise Control LibraryβStep 63 β Translate Reference Controls
Section titled βStep 63 β Translate Reference ControlsβCreate testable internal controls.
Example:
Control ID:IAM-003
Control:Quarterly Privileged Access ReviewStatement:
The IAM team reviews all privileged production access quarterly and removes unauthorized access within five business days.
Step 64 β Define Control Attributes
Section titled βStep 64 β Define Control AttributesβInclude:
Control ID
Objective
Statement
Owner
Operator
Frequency
Population
Evidence
Risk Mapping
Framework MappingStep 65 β Distinguish Control Type
Section titled βStep 65 β Distinguish Control TypeβClassify:
Preventive
Detective
Correctiveand:
Manual
Automated
HybridPhase 12 β Implement Control Gaps
Section titled βPhase 12 β Implement Control GapsβStep 66 β Create Remediation Backlog
Section titled βStep 66 β Create Remediation BacklogβFor every gap:
Gap
Risk
Action
Owner
Target
StatusStep 67 β Implement Controls
Section titled βStep 67 β Implement ControlsβWork with responsible teams.
Examples:
IAMβ MFA / PAM
Securityβ Logging / Monitoring
Engineeringβ Secure SDLC
ITβ Backup / Recovery
GRCβ Supplier SecurityStep 68 β Document Exceptions
Section titled βStep 68 β Document ExceptionsβWhere full implementation is not possible:
Exception βRisk Assessment βCompensating Controls βApproval βExpirationStep 69 β Validate Implementation
Section titled βStep 69 β Validate ImplementationβDo not rely solely on:
Implemented.
Require evidence.
Phase 13 β Establish Evidence Management
Section titled βPhase 13 β Establish Evidence ManagementβStep 70 β Create Evidence Register
Section titled βStep 70 β Create Evidence RegisterβFields:
Evidence ID
Control
Evidence
Owner
Frequency
Period
Location
RetentionStep 71 β Define Expected Evidence
Section titled βStep 71 β Define Expected EvidenceβExamples:
| Control | Evidence |
|---|---|
| MFA | Coverage Report |
| Access Review | Review Record |
| Vulnerability Mgmt | Scan + Ticket |
| Backup | Recovery Test |
| Vendor Review | Assessment |
| Logging | SIEM Coverage |
Step 72 β Establish Evidence Repository
Section titled βStep 72 β Establish Evidence RepositoryβStructure example:
ISO27001/ββββ Governanceβββ Riskβββ SoAβββ Controlsβββ Evidenceβββ Auditβββ Management Reviewβββ Corrective ActionsStep 73 β Protect Sensitive Evidence
Section titled βStep 73 β Protect Sensitive EvidenceβApply:
-
Access control.
-
Encryption.
-
Need-to-know access.
-
Appropriate retention.
Phase 14 β Establish Security Objectives & Metrics
Section titled βPhase 14 β Establish Security Objectives & MetricsβStep 74 β Define Information Security Objectives
Section titled βStep 74 β Define Information Security ObjectivesβExample:
Achieve 100% privileged MFA coverage.
Complete all critical vendor assessments.
Improve critical vulnerability remediation SLA.Step 75 β Define KPI/KRI
Section titled βStep 75 β Define KPI/KRIβExample:
KPI:% Critical vulnerabilities remediated within SLA
KRI:Critical vulnerabilities older than 30 daysStep 76 β Define Owners & Targets
Section titled βStep 76 β Define Owners & TargetsβTrack:
| Objective | Target | Owner | Status |
|---|
Step 77 β Establish Monitoring Cadence
Section titled βStep 77 β Establish Monitoring CadenceβPossible cadence:
Monthly
Quarterly
Annualdepending on metric.
Phase 15 β Perform Pre-Audit Control Readiness Review
Section titled βPhase 15 β Perform Pre-Audit Control Readiness ReviewβStep 78 β Select Critical Controls
Section titled βStep 78 β Select Critical ControlsβPrioritize:
-
IAM.
-
Logging.
-
Vulnerability management.
-
Vendor security.
-
Incident response.
-
Recovery.
Step 79 β Validate Control Design
Section titled βStep 79 β Validate Control DesignβAsk:
Does the control address the risk?
Is scope defined?
Is ownership clear?
Is frequency appropriate?
Does it generate evidence?Step 80 β Validate Operating Effectiveness
Section titled βStep 80 β Validate Operating EffectivenessβCheck actual execution.
Example:
Quarterly Review Required
Q1 βQ2 βQ3 βQ4 βDo not mark this fully effective.
Step 81 β Update SoA Status
Section titled βStep 81 β Update SoA StatusβSoA should reflect actual control implementation.
Phase 16 β Perform Internal Audit
Section titled βPhase 16 β Perform Internal AuditβStep 82 β Establish Audit Program
Section titled βStep 82 β Establish Audit ProgramβDefine:
Scope
Criteria
Frequency
Auditor
ScheduleStep 83 β Maintain Auditor Objectivity
Section titled βStep 83 β Maintain Auditor ObjectivityβAvoid uncontrolled self-audit.
Step 84 β Prepare Audit Plan
Section titled βStep 84 β Prepare Audit PlanβInclude:
-
Clauses.
-
Processes.
-
Controls.
-
Evidence.
-
Interviews.
-
Sampling.
Step 85 β Perform Testing
Section titled βStep 85 β Perform TestingβAudit:
ISMS Clauses+Applicable ControlsStep 86 β Document Findings
Section titled βStep 86 β Document FindingsβUse:
Criteria
Condition
Evidence
Risk
FindingStep 87 β Issue Audit Report
Section titled βStep 87 β Issue Audit ReportβProvide:
-
Executive summary.
-
Scope.
-
Findings.
-
Overall conclusion.
-
Corrective actions.
Phase 17 β Correct Internal Audit Findings
Section titled βPhase 17 β Correct Internal Audit FindingsβStep 88 β Perform Correction
Section titled βStep 88 β Perform CorrectionβAddress immediate issue.
Step 89 β Perform Root Cause Analysis
Section titled βStep 89 β Perform Root Cause AnalysisβAvoid:
Human error.Identify systemic cause.
Step 90 β Develop Corrective Action
Section titled βStep 90 β Develop Corrective ActionβExample:
Problem:Quarterly review missed
Corrective Action:Automate scheduling and escalationStep 91 β Assign Owner & Target
Section titled βStep 91 β Assign Owner & TargetβTrack centrally.
Step 92 β Retest
Section titled βStep 92 β RetestβDo not close solely on owner statement.
Verify evidence.
Step 93 β Close or Reopen
Section titled βStep 93 β Close or ReopenβUse:
Passβ Close
Failβ Continue RemediationPhase 18 β Conduct Management Review
Section titled βPhase 18 β Conduct Management ReviewβStep 94 β Prepare Management Review Pack
Section titled βStep 94 β Prepare Management Review PackβInclude:
Previous Actions
Context Changes
Risk Status
Objectives
Metrics
Audit Results
Incidents
Supplier Risk
Corrective Actions
Improvement OpportunitiesStep 95 β Conduct Formal Review
Section titled βStep 95 β Conduct Formal ReviewβLeadership should participate.
Step 96 β Capture Decisions
Section titled βStep 96 β Capture DecisionsβExample:
Decision:Accelerate PAM implementation
Owner:IAM Director
Target:Q1Step 97 β Capture Resource Needs
Section titled βStep 97 β Capture Resource NeedsβManagement review should address resource constraints.
Step 98 β Maintain Minutes
Section titled βStep 98 β Maintain MinutesβRecord:
-
Attendees.
-
Inputs.
-
Decisions.
-
Actions.
-
Owners.
-
Dates.
Phase 19 β Perform Certification Readiness Assessment
Section titled βPhase 19 β Perform Certification Readiness AssessmentβStep 99 β Reassess Clauses 4β10
Section titled βStep 99 β Reassess Clauses 4β10βVerify:
Implemented
Operating
EvidencedStep 100 β Reconcile Key Artifacts
Section titled βStep 100 β Reconcile Key ArtifactsβCompare:
Risk RegistervsRTPvsSoAvsControl LibraryvsEvidenceResolve contradictions.
Step 101 β Confirm Internal Audit Complete
Section titled βStep 101 β Confirm Internal Audit CompleteβCheck open findings.
Step 102 β Confirm Management Review Complete
Section titled βStep 102 β Confirm Management Review CompleteβCheck decisions and actions.
Step 103 β Review Open Gaps
Section titled βStep 103 β Review Open GapsβClassify:
Certification Blocking
High Priority
Manageable / MonitoredStep 104 β Determine Readiness
Section titled βStep 104 β Determine ReadinessβUse:
Ready
Conditionally Ready
Not ReadyDocument rationale.
Phase 20 β Select Certification Body
Section titled βPhase 20 β Select Certification BodyβStep 105 β Define Certification Requirements
Section titled βStep 105 β Define Certification RequirementsβDocument:
-
Scope.
-
Locations.
-
Target date.
-
Industry requirements.
-
Customer expectations.
Step 106 β Evaluate Providers
Section titled βStep 106 β Evaluate ProvidersβConsider:
Accreditation
Industry Experience
Auditor Competence
Geographic Coverage
Timeline
CostStep 107 β Confirm Audit Schedule
Section titled βStep 107 β Confirm Audit ScheduleβSchedule:
Stage 1
Stage 2
Potential Follow-UpPhase 21 β Prepare for Stage 1
Section titled βPhase 21 β Prepare for Stage 1βStep 108 β Create Stage 1 Evidence Pack
Section titled βStep 108 β Create Stage 1 Evidence PackβInclude:
Scope
Context
Interested Parties
Policy
Risk Methodology
Risk Register
RTP
SoA
Objectives
Internal Audit
Management ReviewStep 109 β Prepare Key Stakeholders
Section titled βStep 109 β Prepare Key StakeholdersβLikely participants:
-
ISMS Manager.
-
GRC.
-
CISO.
-
Relevant process owners.
Step 110 β Track Audit Requests
Section titled βStep 110 β Track Audit RequestsβUse:
| Request | Owner | Due | Status |
|---|
Step 111 β Address Stage 1 Issues
Section titled βStep 111 β Address Stage 1 IssuesβImmediately:
Issue βOwner βAction βEvidence βValidationPhase 22 β Prepare for Stage 2
Section titled βPhase 22 β Prepare for Stage 2βStep 112 β Confirm Stage 1 Actions Complete
Section titled βStep 112 β Confirm Stage 1 Actions CompleteβDo not proceed blindly if significant readiness issues remain.
Step 113 β Build Stage 2 Interview Schedule
Section titled βStep 113 β Build Stage 2 Interview ScheduleβInclude:
Leadership
GRC
IAM
Security Operations
Engineering
IT
HR
ProcurementStep 114 β Prepare Evidence Owners
Section titled βStep 114 β Prepare Evidence OwnersβThey should know:
-
What control they own.
-
How it works.
-
Where evidence exists.
-
Known exceptions.
Step 115 β Prepare Audit Request Tracker
Section titled βStep 115 β Prepare Audit Request TrackerβTrack:
Request ID
Auditor
Owner
Evidence
Time
Status
Follow-UpStep 116 β Perform Evidence Quality Review
Section titled βStep 116 β Perform Evidence Quality ReviewβBefore submission confirm:
Correct Period?
Correct Scope?
Complete?
Sensitive Data Minimized?
Current Version?Phase 23 β Support Stage 2 Audit
Section titled βPhase 23 β Support Stage 2 AuditβStep 117 β Coordinate Opening Meeting
Section titled βStep 117 β Coordinate Opening MeetingβConfirm:
-
Scope.
-
Schedule.
-
Audit team.
-
Communication.
-
Evidence process.
Step 118 β Support Interviews
Section titled βStep 118 β Support InterviewsβDo not coach scripted answers.
Personnel should describe real processes.
Step 119 β Support Control Walkthroughs
Section titled βStep 119 β Support Control WalkthroughsβAuditor may follow:
Risk βControl βProcedure βEvidence βSampleStep 120 β Respond to Findings Professionally
Section titled βStep 120 β Respond to Findings ProfessionallyβIf factual disagreement exists:
-
Clarify requirement.
-
Present evidence.
-
Correct misunderstandings.
Do not hide valid weaknesses.
Phase 24 β Manage Certification Findings
Section titled βPhase 24 β Manage Certification FindingsβStep 121 β Record Every Finding
Section titled βStep 121 β Record Every FindingβMaintain:
Finding ID
Requirement
Classification
Condition
Root Cause
Action
Owner
Target
Evidence
StatusStep 122 β Correct Immediate Issue
Section titled βStep 122 β Correct Immediate IssueβWhere needed.
Step 123 β Perform Root Cause Analysis
Section titled βStep 123 β Perform Root Cause AnalysisβDetermine why failure occurred.
Step 124 β Define Corrective Action
Section titled βStep 124 β Define Corrective ActionβPrevent recurrence.
Step 125 β Submit Evidence
Section titled βStep 125 β Submit EvidenceβFollow certification-body requirements.
Step 126 β Support Follow-Up Verification
Section titled βStep 126 β Support Follow-Up VerificationβWhere required.
Phase 25 β Certification Decision
Section titled βPhase 25 β Certification DecisionβStep 127 β Confirm Closure Status
Section titled βStep 127 β Confirm Closure StatusβEnsure required findings are satisfactorily addressed.
Step 128 β Review Certificate Scope
Section titled βStep 128 β Review Certificate ScopeβVerify wording reflects intended ISMS boundaries.
Step 129 β Record Certification Details
Section titled βStep 129 β Record Certification DetailsβMaintain:
Certification Body
Certificate Number
Scope
Issue Date
Expiry / Cycle Dates
Surveillance SchedulePhase 26 β Transition to Continuous ISMS Operation
Section titled βPhase 26 β Transition to Continuous ISMS OperationβCertification is not the end.
Move immediately to operational maintenance.
Step 130 β Maintain Risk Register
Section titled βStep 130 β Maintain Risk RegisterβUpdate when:
-
Risks change.
-
Controls fail.
-
New technologies appear.
-
Incidents occur.
Step 131 β Maintain RTP
Section titled βStep 131 β Maintain RTPβTrack outstanding treatments.
Step 132 β Maintain SoA
Section titled βStep 132 β Maintain SoAβUpdate after:
New Risk
Control Change
Scope Change
Requirement Change
Supplier ChangeStep 133 β Maintain Evidence Calendar
Section titled βStep 133 β Maintain Evidence CalendarβCollect evidence throughout the year.
Avoid audit-season scrambling.
Step 134 β Maintain Policy Calendar
Section titled βStep 134 β Maintain Policy CalendarβTrack review dates.
Step 135 β Continue Control Testing
Section titled βStep 135 β Continue Control TestingβUse periodic assurance.
Phase 27 β Prepare for Surveillance Audits
Section titled βPhase 27 β Prepare for Surveillance AuditsβStep 136 β Review Previous Findings
Section titled βStep 136 β Review Previous FindingsβConfirm ongoing effectiveness.
Step 137 β Review Changes Since Last Audit
Section titled βStep 137 β Review Changes Since Last AuditβExamples:
New Cloud Provider
Acquisition
New Product
Major Incident
New RegulationStep 138 β Update Audit Package
Section titled βStep 138 β Update Audit PackageβInclude:
-
Updated risks.
-
Updated SoA.
-
Internal audit.
-
Management review.
-
Metrics.
-
Corrective actions.
Step 139 β Verify Continuous Improvement
Section titled βStep 139 β Verify Continuous ImprovementβAuditor should see evidence that the ISMS evolved.
Phase 28 β Recertification Preparation
Section titled βPhase 28 β Recertification PreparationβStep 140 β Reperform Comprehensive Readiness Review
Section titled βStep 140 β Reperform Comprehensive Readiness ReviewβReview the complete ISMS.
Step 141 β Confirm Scope Still Accurate
Section titled βStep 141 β Confirm Scope Still AccurateβBusiness may have changed significantly.
Step 142 β Confirm Control Environment Still Appropriate
Section titled βStep 142 β Confirm Control Environment Still AppropriateβRisks and technology evolve.
Step 143 β Reconcile All Governance Artifacts
Section titled βStep 143 β Reconcile All Governance ArtifactsβEnsure consistency.
Step 144 β Prepare for Recertification Assessment
Section titled βStep 144 β Prepare for Recertification AssessmentβUse the same disciplined evidence and coordination process.
Operational ISO Implementation Checklist
Section titled βOperational ISO Implementation ChecklistβProgram Initiation
Section titled βProgram Initiationβ-
Business driver documented.
-
Executive sponsor identified.
-
ISMS Manager assigned.
-
Governance established.
-
Resources identified.
Context & Scope
Section titled βContext & Scopeβ-
Internal issues documented.
-
External issues documented.
-
Interested parties identified.
-
Requirements captured.
-
Critical services mapped.
-
Dependencies mapped.
-
ISMS scope approved.
-
Risk methodology approved.
-
Risk criteria defined.
-
Acceptance criteria defined.
-
Risk assessment completed.
-
Risk owners assigned.
-
Residual risks documented.
Treatment
Section titled βTreatmentβ-
Treatment strategy selected.
-
Controls selected.
-
Treatment owners assigned.
-
Target dates established.
-
Target residual risk defined.
-
RTP approved.
-
Annex A reviewed.
-
Applicability determined.
-
Inclusion justifications documented.
-
Exclusions justified.
-
Inherited/shared controls documented.
-
Implementation status validated.
-
Owners identified.
-
Risks mapped.
-
Evidence linked.
-
SoA approved.
Controls & Evidence
Section titled βControls & Evidenceβ-
Enterprise controls defined.
-
Owners assigned.
-
Frequencies defined.
-
Evidence expectations defined.
-
Control gaps remediated.
-
Exceptions governed.
-
Evidence repository established.
Performance Evaluation
Section titled βPerformance Evaluationβ-
Security objectives defined.
-
KPIs defined.
-
KRIs defined.
-
Internal audit completed.
-
Audit findings recorded.
-
Corrective actions tracked.
-
Retesting completed.
Management Review
Section titled βManagement Reviewβ-
Review pack prepared.
-
Leadership participated.
-
Decisions documented.
-
Resources reviewed.
-
Actions assigned.
Certification
Section titled βCertificationβ-
Readiness assessment complete.
-
Certification body selected.
-
Stage 1 evidence prepared.
-
Stage 1 issues addressed.
-
Stage 2 interviews scheduled.
-
Evidence tracker ready.
-
Findings remediation process ready.
-
Certification scope verified.
Continuous Operation
Section titled βContinuous Operationβ-
Risk register maintained.
-
RTP maintained.
-
SoA maintained.
-
Evidence collected continuously.
-
Policies reviewed.
-
Controls monitored.
-
Surveillance readiness maintained.
Quick Reference β Certification Readiness Decision Tree
Section titled βQuick Reference β Certification Readiness Decision TreeβISMS Scope Defined? β βββ No β Define Scope β βββ Yes βRisk Assessment Current? β βββ No β Complete Assessment β βββ Yes βRTP & SoA Current? β βββ No β Update β βββ Yes βControls Implemented? β βββ No β Remediate / Govern Exceptions β βββ Yes βEvidence Available? β βββ No β Establish Evidence β βββ Yes βInternal Audit Complete? β βββ No β Perform Audit β βββ Yes βMaterial Findings Closed? β βββ No β Correct & Retest β βββ Yes βManagement Review Complete? β βββ No β Conduct Review β βββ Yes βCertification ReadyRecommended ISMS Repository
Section titled βRecommended ISMS RepositoryβISO27001-ISMS/ββββ 01-Governance/β βββ ISMS-Scopeβ βββ Context-Registerβ βββ Interested-Partiesβ βββ RACIββββ 02-Risk/β βββ Risk-Methodologyβ βββ Risk-Registerβ βββ Risk-Acceptanceββββ 03-Risk-Treatment/β βββ RTPββββ 04-SoA/β βββ Statement-of-Applicabilityβ βββ Risk-Control-Mappingββββ 05-Controls/β βββ Control-Libraryβ βββ Ownershipββββ 06-Policies/ββββ 07-Evidence/ββββ 08-Internal-Audit/ββββ 09-Management-Review/ββββ 10-Corrective-Actions/ββββ 11-Certification/Common Implementation Failures
Section titled βCommon Implementation FailuresβFailure 1 β Starting With Policies
Section titled βFailure 1 β Starting With PoliciesβThe organization writes dozens of policies before understanding scope and risk.
Better:
Contextβ Scopeβ Riskβ Controlsβ PoliciesFailure 2 β Treating ISO as Annex A Only
Section titled βFailure 2 β Treating ISO as Annex A OnlyβClauses 4β10 are central to the ISMS.
Failure 3 β Risk Register Built Only for Audit
Section titled βFailure 3 β Risk Register Built Only for AuditβRisk should drive decisions throughout the year.
Failure 4 β SoA Copied From a Template
Section titled βFailure 4 β SoA Copied From a TemplateβApplicability should reflect actual context.
Failure 5 β No Control Owners
Section titled βFailure 5 β No Control OwnersβControls degrade without accountability.
Failure 6 β Evidence Collected at the Last Minute
Section titled βFailure 6 β Evidence Collected at the Last MinuteβContinuous evidence management is stronger.
Failure 7 β Internal Audit Is Superficial
Section titled βFailure 7 β Internal Audit Is SuperficialβInternal audit should test operation, not just documents.
Failure 8 β Management Review Is a Presentation
Section titled βFailure 8 β Management Review Is a PresentationβManagement should make decisions.
Failure 9 β Corrective Actions Address Symptoms
Section titled βFailure 9 β Corrective Actions Address SymptomsβRoot causes remain.
Failure 10 β Certification Becomes the End Goal
Section titled βFailure 10 β Certification Becomes the End GoalβThe ISMS must continue operating after certification.
Practical GRC Mindset
Section titled βPractical GRC MindsetβA weak ISO implementation asks:
What documents does the auditor want?
A better implementation asks:
What processes and controls do we need to demonstrate conformity?
A mature implementation asks:
How do we build a sustainable management system that continuously connects business requirements, risk, controls, evidence, assurance, leadership, and improvement?
That is the mindset required to operate ISO/IEC 27001 effectively.
Runbook Deliverables
Section titled βRunbook DeliverablesβA completed implementation package should contain:
01 β Business Case & Governance
02 β Context Register
03 β Interested Parties Register
04 β Requirements Register
05 β ISMS Scope
06 β ISMS RACI
07 β ISO Gap Assessment
08 β Risk Assessment Methodology
09 β Information Security Risk Register
10 β Risk Treatment Plan
11 β Statement of Applicability
12 β Enterprise Control Library
13 β Control Ownership Matrix
14 β Evidence Register
15 β Security Objectives & Metrics
16 β Internal Audit Program
17 β Internal Audit Report
18 β Corrective Action Register
19 β Management Review Pack
20 β Management Review Minutes
21 β Certification Readiness Assessment
22 β Stage 1 Evidence Pack
23 β Stage 2 Audit Tracker
24 β Certification Finding Tracker
25 β Surveillance CalendarRunbook Completion Criteria
Section titled βRunbook Completion CriteriaβThe organization is ready to proceed confidently toward certification when:
Scope is defensible
Leadership is engaged
Risk methodology is operational
Risk register is current
RTP is current
SoA reflects reality
Controls are implemented
Evidence is available
Internal audit is complete
Material findings are addressed
Management review is complete
Certification evidence is organized
Control owners understand their responsibilitiesRunbook Complete
Section titled βRunbook CompleteβYou now have a repeatable end-to-end workflow for taking an organization from:
ISO Initiativeto:
Certification-Ready ISMSand then into:
Surveillance βContinuous Improvement βRecertificationThis workflow can be used by GRC Analysts, ISO/IEC 27001 Consultants, ISMS Managers, Security Compliance Analysts, Security Assurance professionals, and internal governance teams implementing ISO/IEC 27001 in enterprise environments.
Whatβs Next?
Section titled βWhatβs Next?ββ‘οΈ Next: Runbook 02 β ISO/IEC 27001 Internal Audit, Nonconformity & Corrective Action Management
In the next and final runbook for this ISO/IEC 27001 module, you will operationalize the ongoing assurance lifecycle:
Build Audit Program βPlan Audit βCollect Evidence βTest Controls βIdentify Nonconformities βPerform Root Cause Analysis βDefine Corrective Actions βTrack Remediation βRetest βClose Findings βFeed Results Into Management ReviewThe runbook will focus on how a GRC or ISMS team manages the internal audit and corrective-action process continuously, rather than treating it only as a pre-certification exercise.