Part III · Chapter 13

Step by step to a management system

Building an information security management system is not a project that gets finished. It is a way of working that has to be started and then kept going. This chapter walks the road there in four phases, from identifying and analysing to following up and improving, with a realistic timeline and a review of the mistakes that most often force a restart.

  • CISOs and security leads

Last reviewed

Chapter 11 argues why ISO 27001 makes a good hub. This chapter answers the next question, how you actually build it, in what order, with what staffing and over what time. That is the question that decides whether the work happens at all, since an organisation that does not know where to start usually starts with the documents, and therefore at the wrong end.

It opens with the preparations, the decisions that need to be taken before the work begins. Scope, ownership, mandate and an honest estimate of available time. Scope is the single most important of these, since a management system meant to cover everything rarely gets finished with anything. Then follow the four phases. Identifying and analysing, mapping assets, stakeholders, requirements and risks so the work rests on a current state. Designing, which is where policies, roles, processes and controls take shape. Using, which is about the way of working becoming part of everyday life rather than a parallel operation alongside the real one. And following up and improving, with internal audits, measurement and management review closing the circle. After that comes a realistic timeline counted in quarters, and a review of the twelve most common mistakes, the least sentimental section of the chapter and the one that saves the most time. The risk analysis the first phase rests on is covered in chapter 14 on risk and gap analysis, and the standard itself in chapter 11.

The relevance is simple. The Cybersecurity Act requires a systematic way of working that can be demonstrated, and there is no shortcut that delivers it. Organisations that try to answer the law with individual measures discover at the first supervisory question that the measures exist but the context that would justify them does not. Whoever instead starts with scope and ownership has a structure to hang every later measure on.

This page shows what the chapter covers and why the order matters. The work in detail, the timeline and the twelve mistakes are in chapter 13 of the book.

The certificate is a starting point, not a goal. The real work begins the day after the audit.

Key insights

  • Scope is decided first. A management system meant to cover everything rarely gets finished with anything.
  • Four phases are enough as a structure. Identify, design, use and follow up, in that order.
  • The documentation is the result of the work, not the work. Whoever starts with the documents builds a facade.
  • The timeline should be counted in quarters, not weeks, and the most common cause of delay is unclear ownership.
  • The certificate marks that the work has started to function, not that it is finished.

Tools that belong to this chapter

The templates and interactive tools are in the Toolbox, free of charge.

  • Template collection

    Policy, risk register and the other documents from appendix A, ready to adapt.

  • System tools

    Platforms that hold the management system together over time.

Read on

Next step

Where does your organisation stand?

The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.