Management systems

ISO 27001 & ISMS: built with your team, not just for your auditor

We help you build an information security management system (ISMS) that fits how your organization already works — and prepare it for ISO/IEC 27001 certification. We do not stop at the gap analysis: we work alongside your team to implement what the ISMS identifies — and help your people understand and run it.

Why ISMS projects often stall

ISO/IEC 27001 is not hard because of its length. It becomes hard when the ISMS lives next to the organization instead of inside it.

  • A consultant delivers templates, but nobody internally knows how to use them
  • Risks, assets and controls sit in disconnected spreadsheets
  • Responsibilities are written down but not lived
  • The Statement of Applicability is filled in once and never touched again
  • Evidence has to be collected in a hurry right before the audit
  • A new tool is introduced even though existing systems could have done the job

What we build together

Everything an ISMS needs for ISO/IEC 27001 — structured so that your team can keep it running.

Scope & context

What does the ISMS cover, which interested parties and requirements matter, and what are your security objectives?

Gap analysis

Where do you stand today against ISO/IEC 27001 — and what is already there that we can build on?

Assets & risks

An asset inventory and a risk assessment method that people can actually apply, plus a risk treatment plan.

Controls & SoA

Selecting and justifying Annex A controls, and a Statement of Applicability that reflects reality.

Policies & procedures

Clear, short policies and procedures written for the people who follow them — not for the shelf.

Roles & responsibilities

Who owns which risk, control and process — agreed with the people involved.

Objectives & KPIs

Measurable security objectives and a small set of meaningful indicators.

Audit readiness

Evidence structure, internal audit, management review and support through the certification audit.

Integrated ISMS support

An ISMS should create action — not just documentation

An ISMS continuously produces work: requirements, risks, findings, objectives. Our support follows what your management system identifies — from the requirement to a measure that is implemented, evidenced and reviewed.

  1. Requirement, risk or finding
  2. Action required
  3. Organizational or technical measure
  4. Implementation
  5. Evidence
  6. Effectiveness review
  7. Improvement

Example: a risk assessment identifies weak authentication

Many consultants would write “implement stronger authentication” into a report and leave. This is what it can look like with us instead:

  1. Requirement understoodWhich systems, users and access paths are affected — and what does “strong enough” mean for this risk?
  2. Existing environment reviewedYour identity provider, VPN, cloud services and applications — often the capability is already licensed.
  3. Options evaluatedSettings in existing tools, organizational rules, open-source or European alternatives if something is missing.
  4. Decision by youYou choose the solution based on a clear comparison of effort, cost and risk reduction.
  5. Implementation supportedRollout plan, coordination with IT and service providers, exceptions handled.
  6. Responsibilities & peopleOwners defined, employees informed or trained where necessary.
  7. Evidence & reviewEvidence collected, effectiveness checked, risk and control status updated in the ISMS.

Examples of what we can help with

This is not a closed catalogue. If an activity, risk, control or improvement comes out of your ISMS, there is a good chance we can help you address it.

Structure

  • Risk and asset management
  • Controls and Statement of Applicability
  • Policies, procedures and process design
  • Information classification
  • Access-control processes
  • Evidence structures

Steering

  • Security objectives and KPIs
  • KPI monitoring
  • Internal audit preparation
  • Management review preparation
  • Corrective actions
  • Documentation maintenance

People

  • Responsibilities and competence
  • Awareness and employee training
  • Incident response planning
  • Workshops and working sessions
  • Supplier security and assessments

Beyond the ISMS

  • Security technology research
  • Vendor, open-source and European alternatives
  • Funding opportunity research
  • AI governance and secure AI
  • Other measures that arise from the ISMS

We do not claim to provide every specialist service ourselves — for example 24/7 SOC, MDR, penetration testing, digital forensics, emergency incident response or legal advice. Where these are needed, we help you define the requirement, find suitable specialists or solutions and integrate the result into your ISMS.

How deep we get involved

From advice to working alongside you

Every engagement is different. Most combine these three kinds of support — and shift over time as your team takes over.

Advise

We explain what is required, what the problem is, which options exist and what we recommend.

Implement together

We work with your team to design processes, create structures, prepare documentation, run workshops and close gaps.

Operate & improve together

We help coordinate recurring activities, follow up on actions, review risks, prepare audits and reviews — and keep the momentum.

Part of the team — not a transfer of responsibility

Working alongside you does not mean we take over your management responsibilities. Risk ownership, process ownership, decisions and legal responsibilities stay with your organization unless something specific is agreed. Our role: help you do the work — and do it well.

How an ISO 27001 project runs with us

  1. Understand

    We learn how your organization works: people, processes, systems, existing documentation and tools.

  2. Gap analysis & plan

    We compare the current state with ISO/IEC 27001 and agree on a realistic roadmap and responsibilities.

  3. Build together

    Risks, controls, policies and processes are developed in workshops with your team — inside your existing systems where possible.

  4. Enable

    We explain the why behind each part and train the people who will run the ISMS day to day.

  5. Internal audit & review

    We run or support the internal audit and management review and close the remaining gaps.

  6. Certification & beyond

    We support you through the certification audit and — if you like — the operation afterwards.

Your ISMS should belong to your organization — not your consultant

We document in your systems, explain every decision and hand over knowledge step by step. The goal is an ISMS your team understands and can run — with us as long as it helps, without us when you are ready.

Building new — or maintaining an existing ISMS?

Organizational adoption

A management system should not just exist. People should use it.

An ISMS can be perfectly documented and still fail — if people see it as bureaucracy, believe security belongs to IT, or only act right before the audit. That is why adoption is part of every implementation we do.

  1. “I have to do this because ISO says so.”
  2. “I understand why this process exists.”
  3. “I understand my role.”
  4. “I understand how this protects our organization.”
  5. “This is part of how we work.”

Adoption comes from more than training

  • Involving process owners when processes are designed
  • Explanations during the work, not only in formal sessions
  • Understandable responsibilities and useful documentation
  • ISMS tasks integrated into existing workflows and tools
  • Less duplicate work and less bureaucracy
  • Management involvement and recurring communication
  • Feedback from employees — and acting on it
  • Automation of repetitive work where it helps

Stronger internal team

Over time your people become increasingly able to manage their responsibilities, recognize risks and changes, maintain processes and evidence, prepare audits and suggest improvements. We can keep supporting you — but your own ISMS maturity should grow.

What you get out of it

  • An ISMS that reflects how you actually work
  • Risks, controls and evidence connected instead of scattered
  • People who know their role and why it matters
  • Readiness for the ISO/IEC 27001 certification audit

Frequently asked questions

What is an ISMS?

An information security management system (ISMS) is the set of policies, processes, responsibilities and controls an organization uses to manage information security risks systematically. ISO/IEC 27001 is the international standard that describes the requirements for such a system.

How long does ISO 27001 implementation take?

It depends on size, scope and starting point. Many small and mid-sized organizations need roughly six to twelve months from kick-off to certification readiness. After the gap analysis we give you a realistic plan instead of a generic promise.

Can we use our existing tools for the ISMS?

Very often, yes. If you already have a knowledge base, document management, ticketing or project tool, large parts of the ISMS can live there. We only suggest additional software where it clearly helps — including our own app.

Do you certify us?

No. Certification is carried out by an independent, accredited certification body. We prepare you for the audit and can accompany you through it — keeping consulting and certification separate is what makes the certificate credible.

Do you take over responsibility for our ISMS?

We help you do the work — we coordinate, prepare, facilitate, implement and follow up alongside your team. Management responsibility, risk ownership, process ownership and decisions stay with your organization, unless something specific has been agreed in the contract. That is also what makes an ISMS work: the people who own the risks understand them.

What if our ISMS identifies something you do not do yourselves — for example a penetration test?

Then we help you define the requirement, find suitable specialists, vendors or open-source options, and integrate the result back into the ISMS. We do not claim to provide every specialist service ourselves (such as 24/7 SOC, penetration testing or forensics), but we make sure the measure is chosen well and the ISMS keeps moving.

What happens after certification?

The ISMS has to keep working: risks are reviewed, controls monitored, internal audits and management reviews repeated, and surveillance audits follow each year. We can support this through ISMS maintenance.

Does ISO 27001 help with NIS2?

Yes. NIS2 requires risk management measures that overlap substantially with ISO/IEC 27001. An ISMS gives you the structure to implement and evidence them. It does not automatically cover every NIS2 obligation, such as registration or specific reporting duties.

Related services

Related in the FeldmannCyber App: Vendor Intelligence

Related reading

Planning ISO 27001?

Tell us where you stand. We will give you an honest view of the effort and a sensible first step.

contact@feldmanncyber.com · +49 (0)151 6275 6121