Question
Which four phases make up the process of building an ISMS, and which classic management cycle do they follow?
Answer
Vorbereitung → Dokumente → Risikomanagement → KVP — following the Plan-Do-Check-Act cycle.
* The four ISMS build phases as a PDCA cycle — Vorbereitung → Dokumente → Risikomanagement → KVP. *
| Phase | Content |
|---|---|
| Vorbereitung (preparation) | Mandate from management, stocktaking, proposal, budget approval |
| Dokumente (documents) | InfoSec policy, issue-specific & system-specific policies, guidelines, approval & communication |
| Risikomanagement | Asset register, risk estimation, risk evaluation, risk treatment, implementation & training |
| KVP (kontinuierlicher Verbesserungsprozess — continuous improvement) | Control, sanctions, improvement, audit, report to management |
The order matters: you cannot write meaningful documents without a mandate, you cannot treat risks you haven't identified against an asset register, and without the KVP loop the whole construction decays.
Tip: KVP is the German term for what ISO calls continual improvement — the "Act" in PDCA. An ISMS is a cycle, never a finished project.
Go deeper:
Demingkreis / PDCA (Wikipedia DE) — KVP als Act im PDCA; Ursprung (Shewhart/Deming) und Einbettung in Managementnormen.
Note saved — thanks!
Question
What happens in the Vorbereitung (preparation) phase of building an ISMS, and why does it come first?
Answer
Securing the management mandate: Auftrag durch GL → Auslegeordnung → Vorschlag an GL → Budget-Gutsprache.
The four chronological steps:
- Auftrag durch GL — an explicit assignment from the Geschäftsleitung (executive management): security starts as a top-down mandate
- Auslegeordnung — stocktaking/situation analysis: what exists, what's required, where are the gaps?
- Vorschlag an GL — a concrete proposal back to management: scope, approach, resources
- Budget-Gutsprache — budget commitment
Why first: an ISMS built bottom-up by enthusiastic IT staff without mandate and budget fails at the first conflict with a business unit. The preparation phase creates the two things every later phase depends on: legitimacy (mandate) and resources (budget). ISO 27001 encodes the same idea in clause 5 — "Leadership and commitment" is a hard requirement, not a nicety.
Note saved — thanks!