Start with scope and business context

Before writing policies, decide what the ISMS is responsible for. Scope determines which people, processes, systems, locations and information are included. For an SME, a clear and realistic scope is particularly important because unnecessary complexity consumes limited management time. The scope should still make business sense: carving out difficult systems purely to make certification easier can create awkward boundaries and weak risk ownership.

Alongside scope, identify interested parties and the legal, contractual and customer expectations that affect information security. This creates the foundation for the risk assessment because it establishes what the organisation is trying to protect and what failure would mean.

Do not leave evidence until the end

Evidence is easiest to collect when the control is being operated. Trying to reconstruct several months of activity just before certification creates unnecessary pressure and usually produces weaker assurance.

Build the risk and treatment model before polishing documents

Create a practical risk assessment method, identify relevant information security risks and agree treatment decisions. The purpose is not to create the largest possible risk register. It is to make important uncertainty visible and decide what action is proportionate. Treatment then drives control selection, ownership, priorities and the Statement of Applicability.

At this point policies become easier to write because they can reflect actual decisions rather than generic wording. A policy should explain the organisation’s required behaviour; procedures and operational records can then show how that behaviour is implemented.

Move from implementation to evidence and assurance

Once controls are operating, begin collecting evidence deliberately. Evidence can include system reports, tickets, logs, review records, training completion, supplier assessments, meeting records and other artefacts that show a control is functioning. It should be current, attributable and easy to relate back to the relevant requirement or risk.

Before certification, complete an internal audit programme and management review. These are not administrative finishing steps. They are the organisation’s own opportunity to identify gaps, assess whether the ISMS is effective and make improvements before an external auditor does.

Make this easier to manage in OrcaComply

OrcaComply keeps the decisions, owners, documents, controls and evidence behind your ISMS connected so the work is easier to manage and easier to explain.

Explore the ISO 27001 workflow →