Management systems

ISMS maintenance: keep your ISO 27001 system working after the certificate

Certification is a milestone, not the finish line. We help you operate and improve an existing ISMS so that it stays current, useful and audit-ready — without a hectic sprint before every surveillance audit.

Sounds familiar?

Most ISMS problems are not in the design. They appear in daily operation, month after month.

  • Policies are outdated and nobody feels responsible
  • Risks have not been reviewed since the last audit
  • Controls exist on paper but are not monitored
  • Evidence is fragmented across mailboxes, drives and tools
  • Supplier reviews are overdue
  • KPIs are defined but not measured
  • Internal audits slip and management reviews become checkbox exercises
  • Corrective actions stay open for months

What ongoing support can cover

You choose the scope. Some customers want a monthly rhythm, others support for specific cycles.

ISMS calendar

A clear annual plan of recurring activities, owners and deadlines — ideally inside your existing tools.

Risk reviews

Regular review of risks and treatment plans, including new systems, suppliers and changes.

Control monitoring

Checking whether controls are implemented and effective, and keeping the SoA current.

Evidence management

A clean structure so that evidence is collected continuously instead of right before the audit.

Policy updates

Keeping policies and procedures current and aligned with how you actually work.

Supplier reviews

Structured review of critical suppliers and service providers.

Internal audits & reviews

Planning and performing internal audits and preparing meaningful management reviews.

Corrective actions

Tracking findings and corrective actions until they are really closed.

Coordination & follow-up

Maintaining the action list, following up on open activities and keeping the ISMS moving between audits.

Measures that come out of it

When a review finds a gap, we help determine and implement the next step — process, technology, vendor or training.

Integrated ISMS support

An ISMS should create action — not just documentation

An ISMS continuously produces work: requirements, risks, findings, objectives. Our support follows what your management system identifies — from the requirement to a measure that is implemented, evidenced and reviewed.

  1. Requirement, risk or finding
  2. Action required
  3. Organizational or technical measure
  4. Implementation
  5. Evidence
  6. Effectiveness review
  7. Improvement

Example: a risk assessment identifies weak authentication

Many consultants would write “implement stronger authentication” into a report and leave. This is what it can look like with us instead:

  1. Requirement understoodWhich systems, users and access paths are affected — and what does “strong enough” mean for this risk?
  2. Existing environment reviewedYour identity provider, VPN, cloud services and applications — often the capability is already licensed.
  3. Options evaluatedSettings in existing tools, organizational rules, open-source or European alternatives if something is missing.
  4. Decision by youYou choose the solution based on a clear comparison of effort, cost and risk reduction.
  5. Implementation supportedRollout plan, coordination with IT and service providers, exceptions handled.
  6. Responsibilities & peopleOwners defined, employees informed or trained where necessary.
  7. Evidence & reviewEvidence collected, effectiveness checked, risk and control status updated in the ISMS.

Examples of what we can help with

This is not a closed catalogue. If an activity, risk, control or improvement comes out of your ISMS, there is a good chance we can help you address it.

Structure

  • Risk and asset management
  • Controls and Statement of Applicability
  • Policies, procedures and process design
  • Information classification
  • Access-control processes
  • Evidence structures

Steering

  • Security objectives and KPIs
  • KPI monitoring
  • Internal audit preparation
  • Management review preparation
  • Corrective actions
  • Documentation maintenance

People

  • Responsibilities and competence
  • Awareness and employee training
  • Incident response planning
  • Workshops and working sessions
  • Supplier security and assessments

Beyond the ISMS

  • Security technology research
  • Vendor, open-source and European alternatives
  • Funding opportunity research
  • AI governance and secure AI
  • Other measures that arise from the ISMS

We do not claim to provide every specialist service ourselves — for example 24/7 SOC, MDR, penetration testing, digital forensics, emergency incident response or legal advice. Where these are needed, we help you define the requirement, find suitable specialists or solutions and integrate the result into your ISMS.

How deep we get involved

From advice to working alongside you

Every engagement is different. Most combine these three kinds of support — and shift over time as your team takes over.

Advise

We explain what is required, what the problem is, which options exist and what we recommend.

Implement together

We work with your team to design processes, create structures, prepare documentation, run workshops and close gaps.

Operate & improve together

We help coordinate recurring activities, follow up on actions, review risks, prepare audits and reviews — and keep the momentum.

Part of the team — not a transfer of responsibility

Working alongside you does not mean we take over your management responsibilities. Risk ownership, process ownership, decisions and legal responsibilities stay with your organization unless something specific is agreed. Our role: help you do the work — and do it well.

How we work together

  1. Health check

    We look at your ISMS as it is today: documentation, risks, controls, evidence, open findings and people involved.

  2. Priorities

    We agree on what needs attention first — usually what matters for the next audit and for real risk reduction.

  3. Operating rhythm

    We set up a recurring rhythm of activities with clear owners, integrated into your existing processes and tools.

  4. Operate together

    We work alongside your team: reviews, workshops, audits and follow-up. We explain, you decide.

  5. Improve

    Findings, incidents and changes feed back into the ISMS so it becomes more useful every cycle.

Part of your team, not an external compliance police force

We work with your information security officer, IT, process owners and management as colleagues. The aim is an ISMS that becomes part of normal operations — and a team that needs less outside help over time.

Organizational adoption

A management system should not just exist. People should use it.

An ISMS can be perfectly documented and still fail — if people see it as bureaucracy, believe security belongs to IT, or only act right before the audit. That is why adoption is part of every implementation we do.

  1. “I have to do this because ISO says so.”
  2. “I understand why this process exists.”
  3. “I understand my role.”
  4. “I understand how this protects our organization.”
  5. “This is part of how we work.”

Adoption comes from more than training

  • Involving process owners when processes are designed
  • Explanations during the work, not only in formal sessions
  • Understandable responsibilities and useful documentation
  • ISMS tasks integrated into existing workflows and tools
  • Less duplicate work and less bureaucracy
  • Management involvement and recurring communication
  • Feedback from employees — and acting on it
  • Automation of repetitive work where it helps

Stronger internal team

Over time your people become increasingly able to manage their responsibilities, recognize risks and changes, maintain processes and evidence, prepare audits and suggest improvements. We can keep supporting you — but your own ISMS maturity should grow.

What you get out of it

  • No more audit panic: evidence is collected continuously
  • Documentation that matches reality
  • Risks and controls that are actually reviewed
  • Management reviews that lead to decisions

Frequently asked questions

What is ISMS maintenance?

ISMS maintenance is the ongoing operation and improvement of an information security management system after it has been introduced: reviewing risks, monitoring controls, updating documents, collecting evidence, running internal audits and management reviews, and closing corrective actions.

What happens after ISO 27001 certification?

An ISO/IEC 27001 certificate is typically valid for three years. In between, the certification body carries out annual surveillance audits, followed by a recertification audit. Throughout this period the ISMS must demonstrably be operated and improved.

Can you take over an ISMS someone else built?

Yes. We start with a health check to understand the existing structure. Where it works, we keep it. Where it does not, we improve it step by step — without rebuilding everything.

Can you act as our external information security officer?

We can take over or support many of the tasks associated with this role in close cooperation with your team. What is sensible depends on your organization, size and regulatory requirements — let us talk it through.

Related services

Related reading

Is keeping your ISMS running more work than it should be?

Tell us what is painful. We will suggest a support model that fits your team.

contact@feldmanncyber.com · +49 (0)151 6275 6121