Begin with the management system
ISO/IEC 27001:2022 concerns an information security management system, or ISMS, using a risk-based approach.1 Preparation therefore involves how your organization makes, operates and reviews security decisions, not just a collection of technical settings.
The current preparation baseline should consider the 2022 standard and its 2024 climate-action amendment.2 The SOC 2 versus ISO 27001 comparison can help explain why the selected output matters. Confirm the applicable edition and assessment expectations with your certification body and advisers. This article is an original readiness guide; it does not reproduce the licensed standard or replace its requirements.
1. Write a scope a reader can understand
Name the activities, locations, systems, people, information and interfaces included in the ISMS. Explain outsourced responsibilities and boundaries. Avoid a vague scope such as “all information” if the actual preparation covers only one service.
Ask whether the scope would make sense to customers and staff. If a shared administrative system supports both included and excluded activities, record the dependency rather than hide it behind the boundary.
For a fictional consultancy, an initial scope might cover delivery of managed client reports, its staff document environment and relevant support providers. Its separate training events might be outside scope, while their use of the same identity system remains an interface to consider.
2. Understand context and interested parties
Identify the business objectives, material dependencies and expectations relevant to information security. Record applicable obligations and commitments with an owner for interpretation. Do not treat every customer questionnaire sentence as an automatically applicable requirement.
BSI's current self-assessment resource includes context, risk treatment, selected controls and performance-evaluation topics.3 Use those as prompts for your own analysis, rather than copying a generic answer into the ISMS.
For the climate amendment, assess relevance to the organization's context and interested-party requirements. Do not invent a universal environmental control set or assume relevance without examining the actual operation.
3. Assign leadership and operating responsibilities
Identify who owns the ISMS, who approves objectives and who can authorize risk acceptance. Assign individual owners to important processes and make their authority clear.
Include resources and competence. A named owner without time or access cannot maintain the system. Staff need to understand the responsibilities relevant to their work, and external providers need clear interfaces and escalation arrangements.
Set practical objectives that can be evaluated. “Improve security” is a direction; a defined outcome with an owner, measurement and review point is easier to manage. Do not promise arbitrary response times or control frequencies merely to make the document sound stronger.
4. Establish a repeatable risk process
Define how risks are identified, analyzed, evaluated and accepted. The business risk assessment guide provides a general method to adapt to the ISMS scope. State scope, consequence dimensions, assessment horizon and the evidence or assumptions behind estimates. Owners should be able to explain why an important scenario received its rating.
Choose acceptance criteria and authority before the team confronts a difficult decision. Separate current exposure from the intended future position after treatments. Record uncertainty as part of the assessment, rather than turn missing information into an artificially favorable result.
Revisit the assessment after material change, not just at a calendar deadline. A new provider, service commitment or region can alter the assumptions used for earlier decisions.
5. Connect treatment decisions to selected controls
A risk-treatment plan explains the response, owner, required work and completion evidence. A Statement of Applicability, commonly shortened to SoA, records selected controls and the rationale for their applicability and implementation position.3
Do not treat the SoA as a list of boxes that must all be checked identically. The decisions should follow the scope, risk analysis and applicable requirements, with proper consideration of the standard's reference controls. Confirm the precise required content against the licensed standard.
For each selected control, identify its design, responsible performer and retained evidence. Keep justified exclusions visible and ensure they are not simply a way to avoid an inconvenient requirement.
6. Gather evidence of operation
| Readiness question | Possible supporting record |
|---|---|
| Is access handled according to the approved process? | Relevant provisioning, review and removal records |
| Are changes managed within scope? | Change decisions, implementation and exception records |
| Are important providers reviewed? | Scoped assessment and acceptance decisions |
| Are recovery assumptions checked? | Authorized exercise results and identified gaps |
| Are responsibilities understood? | Relevant communication and competence records |
| Are problems addressed? | Corrective actions, cause analysis and verification |
These are examples, not a substitute for a scoped evidence request. A policy explains intent; an operational record helps show what happened. Preserve versions, dates, populations and exceptions so reviewers can understand coverage.
Use approved access and retention arrangements. Evidence collection should not create a new unprotected copy of sensitive staff or customer information.
Worked example: a management-review package
This fictional consultancy prepares its first focused leadership review. The ISMS owner assembles a short package rather than a presentation full of green percentages.
| Item | What leadership receives | Decision required |
|---|---|---|
| Scope | Current boundary and a proposed new supplier | Confirm whether the change affects scope |
| Risk | An unresolved recovery dependency | Fund treatment or decide on interim acceptance |
| Evidence | One successful exercise with limited coverage | Approve further checking of excluded records |
| Internal review | Access-process exceptions and their causes | Agree owners, dates and escalation |
| Objectives | Actual measurements and missing data | Revise measurement work without hiding gaps |
The review records decisions and assigned actions. It does not state that the company is certified. An internal discussion is one part of the management system, not the external certification decision.
7. Plan internal evaluation and corrective action
Arrange suitable internal checking with objectivity and competence. A person reviewing their own design should not imply independent assurance. Record the evaluation criteria, scope, procedures, evidence and limitations.
When an issue is found, distinguish immediate correction from action addressing its cause. Verify whether the response worked and retain the result. A new policy or closed task is not automatically sufficient evidence of effectiveness.
Bring relevant evaluation results, changed circumstances and resource needs into management review. The ISMS should show a cycle of decisions, operation, evaluation and improvement.
8. Discuss external assessment readiness
ISO does not itself issue certificates; certification is provided by external bodies.4 Evaluate the body's suitability, scope, accreditation arrangements where relevant and assessment process before entering an engagement.
Request a scoped explanation of the assessment sequence, management responsibilities and recurring work. Do not infer a universal timeline, cost or certificate outcome from a checklist or software score.
If a customer needs a particular certificate scope, confirm that need before committing to the assessment. A certificate for a limited activity should not be marketed as covering unrelated services.
A compact readiness handoff
Prepare the scope and context record, ownership map, risk-method description, risk and treatment records, selected-control rationale, relevant policies and operational evidence. Add internal-evaluation results, corrective actions and management decisions, with missing items stated plainly.
That package makes a professional readiness discussion more productive. Its value is in the supportable relationships between decisions and operation, not in the number of documents or a claim that every risk has disappeared.
Sources and references
-
ISO. ISO/IEC 27001:2022 - Information security management systems (2022). Official overview of the ISMS requirements standard and its risk-based approach; the full standard is separately licensed. ↩
-
ISO. ISO/IEC 27001:2022/Amd 1:2024 - Climate action changes (2024-02-23). Official catalog records the published amendment applying to the 2022 ISMS standard. ↩
-
British Standards Institution. Information Security Management System ISO/IEC 27001 Self-assessment checklist (2025). Provider-issued checklist identifies risk treatment, Statement of Applicability and management-system review topics; it does not replace the licensed standard. ↩ ↩2
-
ISO. Certification. Explains third-party certification and that ISO itself does not issue certificates. ↩

