Readiness guide

The building blocks of an ISO/IEC 27001-aligned ISMS.

A plain-English overview of the management-system themes organisations commonly address when preparing for ISO/IEC 27001 assessment. It is not a substitute for the official standard, legal advice, or a complete implementation plan.

Core readiness themes

Build the system around your real operating context.

Every organisation is different. The appropriate scope, risks, controls, records, and evidence should reflect its services, information, technology, people, locations, contractual commitments, and regulatory environment.

1. Context and scope

Describe the organisation’s relevant internal and external context, interested parties, boundaries, and ISMS scope. Be clear about services, sites, assets, and exclusions.

2. Leadership and direction

Assign accountability, establish an information-security policy, set objectives, and make sure the ISMS is supported at the right level of the organisation.

3. Risk assessment and treatment

Use a repeatable method to identify risks, assess their significance, select treatments, assign owners, and accept residual risk through appropriate governance.

4. Control selection

Choose safeguards that address identified risks. Maintain a clear rationale for applicable controls and how they are implemented, monitored, or excluded.

5. People and operational practice

Support competence and awareness, manage documented information, communicate expectations, and ensure security practices operate in normal business activities.

6. Review and improvement

Measure relevant performance, conduct internal audits, hold management reviews, address nonconformities, and improve the ISMS over time.

Evidence to organise

Make decisions and operation visible.

Assessment is helped by information that shows how the ISMS was designed and how it works in practice. The exact set of records will depend on your context and risk decisions.

  • Scope, policy, objectives, and key responsibilities.
  • Risk method, risk register, treatment actions, and control rationale.
  • Relevant procedures, training or awareness evidence, and operational records.
  • Internal audit, management review, incident, and corrective-action evidence.

Next step

See how the programme moves from application to a registry record.

Read the pathway before submitting an application. A submitted application is reviewed; it is not an automatic certification decision.