ISO 27001 is the international standard for information security management. Getting certified isn't a technical project; it's building a management system.
01. Defining Scope
The first decision is which processes and locations the certificate covers. Too wide a scope stretches the process; too narrow a scope devalues the certificate in customers' eyes.
02. Risk Assessment
Assets are listed and threat and vulnerability analysis is done for each. Risks are prioritised and the controls to apply follow from that. This step is the heart of the standard.
03. Implementing Controls
Access management, backup, change management, supplier security, incident response and awareness training are applied. Most are procedural rather than technical.
04. Documentation
Policies, procedures and records. What an audit looks for is not the practice but the record of the practice. Good practices without records are treated as non-existent in an audit.
05. Internal Audit and Review
An internal audit is mandatory before the certification audit. The management review meeting must also be recorded.
06. A Realistic Timeline
For a mid-sized firm, 6-12 months from zero to certificate is reasonable. Approaches promising a certificate in a short time generally produce a paper system that causes problems at the first surveillance audit.