Implementing an ISMS by Bettina LohrImplementing an ISMS by Bettina Lohr

Implementing an ISMS

Bettina Lohr

Bettina Lohr

My Task

My task was to implement an information security management system in accordance with ISO/IEC 27001:2022 at Helm und Walter IT-Solutions GmbH, an IT consulting service provider and product development company. This typically involves establishing policies that support the achievement of security objectives for the company’s most important assets, weighted according to the CIA triad (integrity, availability, confidentiality), and developing a strategy that safeguards the company’s information assets, identifies vulnerabilities, and continuously addresses them. It also involves more mundane tasks, such as training employees or reviewing logs - and all of that somehow had to fit into the ISMS-system and be tracked by it. Normally this requires the fulltime dedication of a single employee. But that was not my goal, since I had other tasks at that company as well, and was not employed fulltime.
I was free to choose how I wanted to approach this task. At first, I considered using Excel spreadsheets and DOCX files. However, I then transitioned to a more integrated system that can help the company protect its products and assets in the long term—and one that isn’t boring to use.

How I proceeded

As part of my role as an ISB starting in April, I considered exactly what an ISMS for HW would need to look like. From my master’s thesis, in which I had examined the integration of a CMS into an SME, I knew how difficult it is to introduce new structures and systems into a company and how important it is to integrate new tools into the existing infrastructure. That’s why I first focused on the existing tools and processes within the company—which was my job as an ISB anyway. With my knowledge of how audits are conducted (thanks to my certifications and network), I also knew what auditors look for, what they want to see right at the start of an audit, and which tools they prefer. I also knew the typical age range and background of auditors and was able to adapt the UI design accordingly.

The Concept

The Result

Less manual maintenance effort through automation
Faster, more cost-effective audits
A single source of truth + no version conflicts between copies, no outdated information
Systematic implementation of improvements rather than on an ad hoc basis or based on personal preferences
Faster, more reliable response in an emergency thanks to clarity
Simplified scaling across additional management systems

The Features

An Audit tab which gives you an overview and leads you through each step of an audit.

A Risk overview, which leds auditors understand the main risks for the company and how many assets this risk affects.

An Audit calendar, which lends an overview over activities that are due within an audit cycle (and is extendable for 22301, 27701 etc)

And it features an OFI (opportunity for improvement)- tracking, which is default for any change management system. Included are NIS2-relevant deadlines, which will become important once the company scales and is obligated to abide by those rules as well.

For quick checks I connected it with the companies LLM that gives you a fast response on the companies policies, without you having to dig into policies.

And last but not least it lists critical news that might be important for the company to read.

Like this project

Posted Jul 23, 2026

As ISB was assigned the task to implement such a system, an ISMS. After first analyzing the processes at the company I decided for an architecture.

Likes

0

Views

1

Timeline

Apr 1, 2026 - Aug 31, 2026

Clients

Helm & Walter IT-Solutions