Skip to main content
GMI-TECHNOLOGIES: A GMI-INVESTMENTS Company
Back to news

ISO 27001: the first 10 actions to take when launching your project

Most ISO 27001 certification projects don't slip because the standard is too demanding β€” they slip because the starting point was poorly calibrated: a fuzzy scope, evidence collected in a last-minute scramble, a statement of applicability written to tick boxes. Here are the first ten concrete actions to take, in order, to start on solid ground.

The first four actions depend only on internal decisions

  1. Create your organization and set up the workspace. Create the tenant, invite the first users, assign roles (owner, contributor, reader). Expected outcome: an isolated, ready workspace with access distributed.
  2. Appoint the project owner. Designate a CISO or security lead as the mission's owner. Expected outcome: a single, accountable point of contact.
  3. Define the certification scope. Document the sites, activities and systems covered, explicitly excluding what isn't, with a justification for each exclusion. Expected outcome: a written, dated scope the board can validate.
  4. Secure executive sponsorship. Formalize the management commitment letter and a first-level security policy. Expected outcome: an official mandate β€” the condition for the project's survival over time.

The next six actions are technical, and only make sense once the first four are validated

  1. Map your assets. Build the asset inventory (infrastructure, applications, data), with an identified owner for each. Expected outcome: a usable inventory, the foundation of the entire risk analysis.
  2. Launch a first technical scan campaign. Authorize, then run, a network discovery, vulnerability detection and cloud posture campaign on the defined scope. Expected outcome: a real technical baseline, not a declarative one.
  3. Activate the ISO/IEC 27001:2022 framework and the relevant crosswalks. Select the framework and activate the crosswalks that matter for your context (PCI-DSS, GDPR, NIST CSF). Expected outcome: a cross-framework assessment base ready to be filled in.
  4. Initialize the risk register. Create the first entries from the asset inventory. Expected outcome: a first, even incomplete, risk map to refine later.
  5. Generate a draft Statement of Applicability (SoA). Start from a reasoned proposal based on the risk analysis under way, rather than a blank page. Expected outcome: a working document to iterate on.
  6. Schedule the dry-run audit and generate the first report. Set an internal audit date 60 to 90 days out and produce a first report to measure the gap. Expected outcome: a concrete calendar and an objective measure of what's left.

Don't try to close all ten in one week

Order matters more than speed: a poorly scoped action 3 invalidates everything that follows. Block half a day for actions 1 to 4, which depend only on internal decisions, and move into the technical actions (5 to 10) as soon as the owner and the scope are validated by management.

AuditForge, our AI-assisted ISO 27001 audit platform, covers these ten actions in a single flow β€” get in touch for a first conversation about your certification path.