LOGBOOK

HELP

1 / 24
Other keys: showSpace: good1-4: rate0: skip5: flag

Question

Which four phases make up the process of building an ISMS, and which classic management cycle do they follow?

Answer

Vorbereitung → Dokumente → Risikomanagement → KVP — following the Plan-Do-Check-Act cycle.

Four ISMS build phases as a cycle: Vorbereitung, Dokumente, Risikomanagement, KVP.

* The four ISMS build phases as a PDCA cycle — Vorbereitung → Dokumente → Risikomanagement → KVP. *

Phase Content
Vorbereitung (preparation) Mandate from management, stocktaking, proposal, budget approval
Dokumente (documents) InfoSec policy, issue-specific & system-specific policies, guidelines, approval & communication
Risikomanagement Asset register, risk estimation, risk evaluation, risk treatment, implementation & training
KVP (kontinuierlicher Verbesserungsprozess — continuous improvement) Control, sanctions, improvement, audit, report to management

The order matters: you cannot write meaningful documents without a mandate, you cannot treat risks you haven't identified against an asset register, and without the KVP loop the whole construction decays.

Tip: KVP is the German term for what ISO calls continual improvement — the "Act" in PDCA. An ISMS is a cycle, never a finished project.

Go deeper:

or press any other key

Question

What happens in the Vorbereitung (preparation) phase of building an ISMS, and why does it come first?

Answer

Securing the management mandate: Auftrag durch GL → Auslegeordnung → Vorschlag an GL → Budget-Gutsprache.

The four chronological steps:

  1. Auftrag durch GL — an explicit assignment from the Geschäftsleitung (executive management): security starts as a top-down mandate
  2. Auslegeordnung — stocktaking/situation analysis: what exists, what's required, where are the gaps?
  3. Vorschlag an GL — a concrete proposal back to management: scope, approach, resources
  4. Budget-Gutsprache — budget commitment

Why first: an ISMS built bottom-up by enthusiastic IT staff without mandate and budget fails at the first conflict with a business unit. The preparation phase creates the two things every later phase depends on: legitimacy (mandate) and resources (budget). ISO 27001 encodes the same idea in clause 5 — "Leadership and commitment" is a hard requirement, not a nicety.

or press any other key