My task was to implement an information security management system in accordance with ISO/IEC 27001:2022 at Helm und Walter IT-Solutions GmbH, an IT consulting service provider and product development company. This typically involves establishing policies that support the achievement of security objectives for the company’s most important assets, weighted according to the CIA triad (integrity, availability, confidentiality), and developing a strategy that safeguards the company’s information assets, identifies vulnerabilities, and continuously addresses them. It also involves more mundane tasks, such as training employees or reviewing logs - and all of that somehow had to fit into the ISMS-system and be tracked by it. Normally this requires the fulltime dedication of a single employee. But that was not my goal, since I had other tasks at that company as well, and was not employed fulltime.