77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide77 officer roles, all coveredArt. 33 GDPR, 72 hours to report a breach93 controls under ISO/IEC 27001:2022905 ready-to-run audit templates in the workspace§ 130 OWiG, supervisory duty of the management boardOfficer appointment letter, signed, filed, evidencedOne workspace for tasks, trainings, audits, documentationDIN 14095 fire protection plans, standardisedEU AI Act, the first horizontal AI regulation worldwide
Information security management system: construction without a file graveyard
IT Security & NIS-2

Information security management system: construction without a file graveyard

30 August 202613 min readBy Lena Vogt
CIVAC

An information security management system is not a collection of documents, but a recurring operational process with an owner, deadline and audit trail. The article shows how you can bring 93 controls into everyday life without sinking into the pile of files or going over your budget.

Since the revision of ISO/IEC 27001 on October 25, 2022, an information security management system (ISMS) has become significantly more than a collection of documents in a SharePoint folder. The standard requires a risk-based, regularly reviewed control process for the information security of the entire organisation, including the supply chain, for which top management is actively responsible. Appendix A was reduced from 114 to 93 controls and at the same time divided into four thematic clusters, which makes it easier to use in medium-sized companies without reducing the depth of testing. The transition period from the previous version 27001:2013 ends on October 31, 2026, so that current certificates must be migrated to the new version with the next re-audit at the latest, otherwise there is a risk of losing the certificate and a complete new audit process.

This article shows how an ISMS can be set up pragmatically, neatly interlinked with the role of the information security officer and embedded in everyday life, without the classic one Creating a file graveyard or overloading the internal team with PowerPoint maintenance. CIVAC operates a Compliance Platform and Officer-as-a-Service: Licence the workspace for your internal representatives, or have our representatives order it. Both models end with audit-proof proof: appointment certificate, signed, filed, verifiable to supervisors, certifiers and customers.

Key Takeaways

  • ISO/IEC 27001:2022 requires 93 controls in four clusters and a risk-based control process for which top management is responsible, not just documents.
  • The transition period ends on October 31, 2026; The next re-audit must be migrated to the new version at the latest.
  • A realistic ISMS setup in medium-sized companies takes 12 to 18 months including risk analysis, implementation of measures and internal audit.

What an information security management system really does

According to ISO/IEC 27001:2022, an information security management system describes the documented, planned-controlled handling of an organisation with risks to the confidentiality, integrity and availability of its information. The standard requires a scope, an information security guideline, a risk assessment and treatment, a statement of applicability (SoA) and an internal audit and management review system. These six elements form the skeleton of the ISMS and are explicitly checked by the certifier in every audit because they demonstrate the organisation's ability to manage.

The ISMS is neither a pure IT task nor a project with a clear end. It is a recurring control process that typically runs every year: reassess risks, adapt measures, check effectiveness, incorporate lessons learned into the management review. Anyone who sets up the ISMS as a one-off project will fail in the surveillance audit after 12 months at the latest because there are no updates and the certifier can no longer reconcile the Statement of Applicability with reality. CIVAC maps this annual rhythm in the workspace and links each control with owner, deadline, evidence and effectiveness assessment. Anyone looking for an external information security officer role will already find the right documents, audit templates and a clear reporting line to management in the platform. This means that the ISMS becomes a resource, not a file folder. Others run compliance like a filing cabinet. We run it like software. In practice, a monthly ISB status report with management proves effective, in which open findings, progress of measures and newly identified risks are discussed in a consolidated manner in 30 minutes, without the management review having to contend with surprises at the end of the year. The platform documents every status situation with a time stamp and those responsible so that the supervisory authority can understand a complete history.

The ISO/IEC 27001:2022 revision: what specifically has changed

The revision of ISO/IEC 27001 from October 25, 2022 has significantly changed the structure of Annex A. 114 controls in 14 domains became 93 controls in four clusters: organisational controls (37 controls), personnel-related controls (8 controls), physical controls (14 controls) and technological controls (34 controls). In addition, 11 new controls were introduced, including Threat Intelligence (5.7), Information Security for Cloud Services (5.23), ICT Readiness for Business Continuity (5.30), Data Masking (8.11) and Web Filtering (8.23). These additions take into account the realities of modern IT architectures without inflating the standard.

The transition period ends on October 31, 2026. Organisations with a valid certificate according to 27001:2013 must have migrated to the new version no later than in the last surveillance audit before this deadline or in the re-audit. In practice, this means a gap analysis between the controls of both versions, an update of the Statement of Applicability and a careful comparison of the existing risk analysis with the new controls. CIVAC has already stored the 93 controls in a structured manner in the workspace and links them to the 490 ready-to-use audit templates. More about the migration can be found in the CIVAC overview of the ISO 27001:2022 transition. Audit-proof, documented, ISO-proof arises from the consistent application of this structure and not from the selective updating of individual Word documents that no one keeps track of in version form. The migration to 27001:2022 is not just a document exercise, but a technical reassessment, because new controls such as Threat Intelligence and ICT Readiness for Business Continuity require new processes in terms of content and not just an entry in the Statement of Applicability. CIVAC provides the gap list of the 11 new controls in its own template and links it to the existing measures.

Scope, guidelines, risk analysis: the foundation

The construction of an ISMS begins with defining the area of ​​application. The scope determines which locations, business processes, information objects and suppliers are included in the ISMS. A scope that is too narrow leads to credibility problems for the certifier; a scope that is too broad creates effort without added value. The information security policy is signed by top management and describes the strategic security goals, responsibilities and commitment to continuous improvement. It is the political document against which the certifiers first measure management in every audit.

The risk analysis is the actual operational core. It identifies threats, assesses the probability of occurrence and the amount of damage, defines a risk acceptance threshold and assigns a treatment option to each risk above the threshold: avoidance, reduction, transfer or acceptance. The Statement of Applicability (SoA) then documents which of the 93 controls are applicable in the specific case and which are excluded for understandable reasons. CIVAC provides a standardised template for risk analysis that is linked to the controls so that the measures are not lost in a separate Excel list, but are assigned to the Statement of Applicability directly in the workspace. Deadline runs from decision. The effectiveness of the measures is continuously measured in subsequent periods and evaluated in a consolidated manner once a year in the management review. A well-maintained risk register is therefore the actual control instrument of the ISMS and not the statement of applicability alone, which without a living risk register quickly degenerates into a pure compliance theater that no longer has any substance in the audit. CIVAC connects the risk register with the owner structures and uses a consistent rating scale across all areas, so that the comparability of risks between locations and business areas is maintained and the management review is reliable.

Statement of applicability and action plan

The Statement of Applicability is the central document in the ISMS audit. It lists each of the 93 controls, notes whether it is applicable, describes the implementation and refers to the associated evidence. A good SoA is no longer than 20 to 30 pages, but precise: each entry refers to a procedural instruction, a protocol or a technical configuration document. During the audit, the certifier checks samples from the SoA and expects that the references are valid. Anyone who works with phrases here will fall into the post-audit loop and delay certification by months.

The action plan translates the risk treatment into concrete tasks with owners, deadlines and effectiveness indicators. Typical measures range from the introduction of an identity and access management system (Control 5.15, 5.16) to the encryption of mobile devices (Control 8.24) to hardening the backup strategy (Control 8.13). CIVAC links every measure in the workspace with the 490 ready-to-use audit templates and documents the progress in an audit-proof manner. Anyone who ends up with 80 PDF pages in the action plan with no person responsible has not built the ISMS, but simply described it. The appointment certificate, signed, filed, verifiable, remains the maxim against which every action plan in an emergency is measured because it forms the bridge between the file and actual responsibility. The action plan is discussed with management and line managers in regular status meetings, ideally every four weeks, so that delays do not only become apparent during the audit, but can be identified and addressed during the year. The platform records every status transition in an audit-proof manner, so that the certifier can understand the complete life cycle of each measure during the audit without providing further evidence. The platform also provides a dashboard that sorts the progress of measures by risk cluster and shows management at a glance where action needs to be taken.

The role of the information security officer (ISB)

ISO/IEC 27001:2022 does not require the appointment of an ISB by name, but does require the assignment of clear responsibilities for information security. In German practice, the role of the information security officer has become established because it clearly represents the interface between IT, management and specialist departments. NIS-2 (implemented in NIS2UmsuCG on October 1, 2026) and the KRITIS umbrella law draft require personalized responsibility anyway, so that the appointment of an ISB becomes de facto mandatory as soon as a company falls under NIS-2 or works with KRITIS suppliers. The appointment in written form with task descriptions and representation regulations is now the market standard.

The ISB is not the CISO, even if both roles can be combined in one person in smaller organisations. The ISB is a technical staff role without the authority to give instructions to the line, with a duty to report to the management and with the task of maintaining the ISMS, auditing it and defending it in the management review. Licence the workspace for your internal representatives, or have our representatives order it. CIVAC offers both models in parallel and ensures that the appointment certificate, the reporting line, the representation regulation and the training plan are stored in the workspace so that an external certifier can immediately check the evidence in the sample without waiting a long time for evidence research. In group structures, the reporting line must be defined particularly carefully because otherwise the responsibilities between group security, subsidiary and business area overlap and in an emergency the supervisory authority cannot identify a clear address for the incident. CIVAC accompanies the clarification of the reporting line with its own workshop template and documents the decision as an attachment to the appointment certificate, so that the line is transparent from day one.

Internal audit, management review and continuous improvement

The internal audit is the strict self-examination of an ISMS. It typically takes place once a year, covers all areas of the scope and documents findings, potential for improvement and non-conformities. The auditors must be independent of the area being audited, which in small organisations can often only be achieved through external auditors or through job rotation. The internal audit provides preparation for the external certification audit and identifies the weak points that the certifier will most likely address.

The management review is the annual meeting in which top management evaluates the performance of the ISMS. According to Chapter 9.3 of the standard, mandatory topics include the status of risk treatment, the result of the internal audits, the feedback from those involved, the effectiveness of the measures and the need for change for the subsequent period. A management review without documented resolutions is not a management review, but an appointment in the calendar. CIVAC provides a template for the management review protocol and links the resolutions directly to the measures that can be derived in the action plan, so that continuous improvement does not appear unclarified in the next audit. The auditor calls, the evidence is ready., and the evidence contains resolutions, owners and deadlines, not just slides from a PowerPoint meeting. The annual rhythm is not a manual ritual, but a formal obligation from Chapter 9.3 of the standard and can therefore be verified; The management review minutes are presented first in the audit and often set the tone of the entire audit. CIVAC delivers the audit checklist, audit report template and management review agenda as part of the 490 ready-to-use audit templates, significantly reducing preparation time.

ISMS and NIS-2: the interlocking of duties

NIS-2 requires a minimum level of information security management, including risk analysis, reporting of significant security incidents and training requirements, for around 29,500 affected companies in Germany. Anyone who already operates an ISMS according to ISO/IEC 27001:2022 covers around 70 to 80% of the NIS 2 requirements and, above all, needs a clean integration of the two worlds for compliance. The 24-hour early warning and the 72-hour follow-up report according to Art. 23 NIS-2 must be embedded in the ISMS incident response process so that the report is not a separate obligation next to the ISMS.

CIVAC stores the NIS-2 reporting path in the workspace and links it with the corresponding controls of ISO 27001:2022, in particular with Control 5.24 (Information Security Incident Management Planning and Preparation), Control 5.25 (Assessment and Decision on Information Security Events) and Control 5.26 (Response to Information Security Incidents). This creates a consolidated escalation path that serves both sets of rules at the same time. Fines according to NIS-2 range up to 10 million euros or 2% of global annual turnover for essential institutions, and up to 7 million euros or 1.4% of turnover for important institutions. An ISMS without NIS 2 integration is incomplete in 2026, an NIS 2 concept without an ISMS foundation cannot be verified and, in case of doubt, provides the supervisory office with too many points of attack for inquiries. CIVAC explicitly documents every interface between ISMS and NIS-2 so that the certifier on one side and the regulator on the other check the same database without the organisation having to maintain two parallel sets of files. The connection with the data protection officer is also stored in the workspace, so that data breaches according to Art. 33 GDPR and security incidents according to NIS-2 are treated in a consolidated escalation path.

Time, cost and realistic implementation paths

Setting up an ISMS in medium-sized companies typically takes 12 to 18 months from the kick-off meeting to the successful certification audit. In the first three months, the scope, guidelines, risk analysis and statement of applicability are created. In months 4 to 9, the measures from the action plan will be implemented, technical controls will be implemented and training will be rolled out. The internal audit, the maturity assessment and the first management review take place in months 10 to 12. The certification audit itself is carried out in two stages: Stage 1 (document review) and Stage 2 (on-site audit).

The costs for setting up an ISMS vary significantly depending on the size of the company. Realistic figures for 2026: for a company with 50 to 200 employees between 35,000 and 90,000 euros for the implementation, plus 8,000 to 18,000 euros for the certification audit itself. In addition, there are the ongoing costs for the ISB role, for training and for monitoring audits in the following years. CIVAC noticeably reduces the implementation effort through the 490 ready-to-use audit templates, through the structured 93 controls in the workspace and through an external ISB order within 2 working days, instead of the classic 2 to 6 week waiting time on the market. This shifts the structure away from PowerPoint advice towards templates that can be used productively from day 1 and a long-term, supporting platform structure. If you clearly separate at the beginning which tasks are covered internally and which are external, you avoid the typical cost surprises in the ninth month of the project and can base the budget discussion with management early on on concrete figures instead of on perceived estimates. CIVAC also offers an agreed service level for ordering the ISB, so that the formal requirements for the ISMS are met within 2 working days and the technical implementation can start in parallel.

From concept to routine: this is how you make your ISMS productive

An ISMS is only successful if it functions in day-to-day business and does not exist as a parallel world alongside operational operations. This is achieved through three levers: firstly, a platform that links every measure with the owner, deadline and evidence. Secondly, a clear ISB role with an appointment document, reporting line to management and sufficient training. Thirdly, an annual rhythm of risk analysis, adjustment of measures, internal audit and management review, which is adhered to regardless of day-to-day business and does not stop after the first 18 months as soon as the certificate is issued.

CIVAC operates this three-lever logic as a compliance platform and officer-as-a-service. If you want to make your ISMS productive now or complete the transition to ISO/IEC 27001:2022 before the deadline of October 31, 2026, write to info@civac.de or use the contact form on civac.de. Turn reading into an assignment. The initial discussions typically last 30 minutes, an ISB is ordered within 2 working days and the onboarding ends with a workspace in which the 93 controls are stored in a structured manner, the Statement of Applicability is available as a template and the NIS 2 reporting path is live from day 1. This means that the ISMS becomes routine, not a document graveyard. EU data residency is consistently ensured for CIVAC. With the workspace, the discussion with management shifts from the abstract compliance risk to a concrete list of measures that shows at all times who will complete which task by when and what evidence has already been provided for this. A productive ISMS is therefore not the privilege of large corporations with an expanded compliance department, but rather an achievable routine for medium-sized organisations that want to start with a clear scope and a suitable platform and work without a desk-work culture.

FAQ

What is the difference between an ISMS and an ISO/IEC 27001 certification?

An ISMS is the control system for information security, the ISO/IEC 27001 certification is the external proof by an accredited certifier that this system meets the standard requirements. You can operate an ISMS without certification, but not the other way around.

How many controls does ISO/IEC 27001:2022 require?

Annex A of ISO/IEC 27001:2022 includes 93 controls in four clusters: 37 organisational, 8 human resources, 14 physical and 34 technological controls. This means that the previous version 27001:2013 was significantly streamlined and restructured with 114 controls in 14 domains.

By when do companies have to migrate to the new version 27001:2022?

The transition period ends on October 31, 2026. The next re-audit or surveillance audit before this deadline must migrate to the new version at the latest. Anyone who misses this risk losing the certificate and having to go through a complete new audit process.

How long does it take to set up an ISMS in a medium-sized company?

It is realistic to expect 12 to 18 months from the kick-off meeting to the successful certification audit. The first three months are used for scope, guidelines and risk analysis, months 4 to 9 are for implementing measures, months 10 to 12 are for internal audit and management review.

How much does it cost to implement an ISMS 2026?

For companies with 50 to 200 employees, the implementation costs in 2026 will be between 35,000 and 90,000 euros. In addition, there are 8,000 to 18,000 euros for the actual certification audit as well as ongoing costs for the ISB role, training and annual monitoring audits in subsequent years.

Do you need an ISB for ISO/IEC 27001:2022 certification?

The standard does not require an ISB by name, but requires clear responsibilities for information security. NIS-2 and KRITIS specifications actually make the appointment of an ISB mandatory. CIVAC appoints external ISB within 2 working days with an appointment certificate, representation regulations and reporting line to the management.

No obligation

Sounds like a lot of work?

Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.

Turn this into a mandate.

Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.

Related articles