ISMS

ISMS After Certification: How to Keep Operations Running

TL;DR
  • The surveillance audit takes place annually and checks whether the ISMS is actively operated. An ISMS that has not been developed further since certification is immediately noticeable.
  • Ongoing operations require a fixed rhythm: monthly status checks, quarterly risk assessment updates, semi-annual policy reviews, and an annual management review.
  • The greatest danger is not a specific omission but the gradual fading of attention. When the ISMS becomes just a mandatory program for the ISM, it slowly dies.
  • Continuous improvement is not a platitude but a standard requirement. You must demonstrate that you learn from audits, incidents, and changes and develop the ISMS further.
  • The effort for ongoing operations is 15 to 25 percent of the build effort. This is significant but plannable and far less than a complete rebuild after decay.

The Post-Certification Void

You made it. Months of preparation, dozens of policies, a complete risk assessment, training for all employees, an internal audit, a management review, and finally the certification audit with a positive result. The ISO 27001 certificate hangs on the wall, sales uses it in customer communications, and management is satisfied.

And then something dangerous happens: everyone breathes a sigh of relief. The ISM takes care of things that fell behind during the ISMS project. The business departments are glad the workshops are over. Management has checked off the topic. The ISMS exists formally, but nobody actively works on it anymore.

This post-certification void is so widespread that experienced auditors look for it first when they come for the surveillance audit. They look at the timestamps: when was the risk assessment last updated? When did the last management review take place? When was the last policy change? If all date stamps are from the certification year and nothing has happened since, that is a clear signal that the ISMS lives on paper but not in practice.

The Certification Cycle: What Happens When

To plan operations, you must understand the rhythm of the certification cycle.

The Initial Certification Audit

The initial certification audit consists of Stage 1 (document review) and Stage 2 (on-site audit). After a successful Stage 2, you receive the certificate. It is valid for three years.

Surveillance Audit Year 1 (approximately 12 months after certification)

The first surveillance audit reviews a portion of the standard requirements and Annex A controls. The scope is smaller than the initial certification audit, but the auditor expects the ISMS to have been actively operated since certification. They will specifically ask about changes: What has changed in the organization? What new risks exist? Which measures have been implemented? What incidents occurred?

Surveillance Audit Year 2 (approximately 24 months after certification)

The second surveillance audit reviews further areas. Together with the first surveillance audit, the entirety of the standard requirements should be covered. The auditor will dig deeper than in the first surveillance audit and want to see more operational evidence.

Recertification Audit (approximately 36 months after certification)

Before the three-year certification cycle expires, the recertification audit takes place. It is more comprehensive than the surveillance audits and similar in scope and depth to the initial certification audit. After successful completion, the certificate is extended for another three years.

The Five Pillars of Ongoing ISMS Operations

Ongoing ISMS operations can be divided into five core activities that must take place on a regular schedule.

Pillar 1: Keeping the Risk Assessment Current

The risk assessment is not a one-time document but an ongoing process. You must update it whenever something changes in the organization or threat landscape.

Event-driven updates. Whenever a significant event occurs, check whether the risk assessment is affected. Such events include: introduction of new IT systems, changes in organizational structure (merger, spin-off, new location), new customer requirements, security incidents in your own organization or in the industry, new regulatory requirements, or changes in the supply chain.

Regular updates. At least once per year, conduct a complete review of the risk assessment. For each risk, check: Is it still relevant? Has the likelihood changed? Has the impact changed? Are the measures still effective? Are there new risks that were not previously captured?

Practical tip: Schedule a brief quarterly risk check. This is not a full run-through but a focused review: Have new assets been added? Were there incidents suggesting previously unrecognized risks? Has the threat landscape changed? This quarterly check prevents the annual review from becoming a mammoth project because a full year of changes has accumulated.

Pillar 2: Tracking and Closing Measures

From the risk assessment, audits, and day-to-day operations, measures arise that must be implemented. A functioning measure management system is the engine of the ISMS.

Every measure needs an owner and a due date. This sounds self-evident but is often neglected. A measure like "improve network segmentation" without a responsible person and without a deadline will never be implemented.

Regular tracking. The ISM checks the status of all open measures monthly. In an ISMS tool like ISMS Lite (ab 500 Euro pro Jahr oder als Einmalkauf für 2.500 Euro), due dates can be automatically monitored and reminders sent to the responsible parties. Overdue measures are escalated. Measures that are repeatedly postponed indicate a structural problem (insufficient resources, unclear responsibility, lack of prioritization) and must be discussed with management.

Effectiveness review. An implemented measure is not automatically an effective measure. You must check whether the measure actually reduced the addressed risk. This can be a technical review (vulnerability scan after hardening), a process review (spot check whether the new process is practiced), or a KPI analysis (has the phishing simulation click rate decreased?).

Pillar 3: Maintaining and Reviewing Policies

Policies are living documents. They must be regularly reviewed and updated when necessary.

Review rhythm. Schedule an annual review for each policy. In practice, it is advisable to distribute reviews throughout the year rather than reviewing all policies at once. If you have 15 policies, review one to two per month.

Triggers for changes. Independent of the regular review, policies must be updated when the underlying processes or technologies change, when new regulatory requirements arise, when an audit identifies a weakness in the policy, or when organizational structures change.

Communicating changes. An updated policy that nobody knows about is worthless. Ensure that policy changes are actively communicated — to affected employees and, for material changes, to the entire organization.

Pillar 4: Maintaining Awareness

Security awareness is not a one-time event but an ongoing program. The training from the certification year is not sufficient for the next three years.

Annual mandatory training. All employees complete an awareness training once per year. The content should evolve from year to year, address new threats, and reference current incidents (internal or from the industry).

Onboarding new employees. Every new employee is informed and trained on information security policies as part of onboarding. This must happen systematically, not as "please read these ten documents."

Regular impulses. Between annual trainings, keep the topic present through brief impulses: monthly newsletters, posters, short video clips, phishing simulations, or themed campaigns (for example, a "clean desk week").

Phishing simulations. Conduct phishing simulations at least quarterly. They serve simultaneously as a training measure and a KPI for the effectiveness of the awareness program.

Pillar 5: Conducting Audits and Management Reviews

Internal audits and management reviews are the formal review and steering mechanisms of the ISMS. Both are mandatory requirements of ISO 27001.

Internal audit. Conduct at least one internal audit per year. The audit checks whether the ISMS processes work as described and whether standard requirements are met. The internal audit should be conducted by someone who is not directly responsible for the processes being audited. If the ISM is the only person with ISMS competence in the organization, commission an external auditor for the internal audit.

Management review. The management review takes place at least once per year and is led by executive management. It covers: the status of the ISMS, the results of the risk assessment, the results of internal and external audits, the status of measures, relevant incidents, changes in the organization's context, and opportunities for improvement.

The management review is the moment when executive management exercises its ongoing responsibility for information security. It must not be a perfunctory exercise where the ISM reads a report and everyone nods. It must be a substantive discussion that leads to decisions.

The ISMS Annual Calendar

A concrete annual calendar helps you plan and track the various activities. Here is an example for a company after initial certification.

Month Activity
January Annual planning: define ISMS objectives for the year, confirm budget, plan audit program
February Policy review batch 1 (3 to 4 policies), awareness impulses
March Quarterly risk check, phishing simulation, measure status review
April Policy review batch 2, cumulative training for new employees
May Update supplier assessments, review technical controls
June Quarterly risk check, phishing simulation, semi-annual status report
July Policy review batch 3, awareness impulses
August Internal audit (preparation and execution)
September Internal audit (completion), address findings, phishing simulation
October Full risk assessment update, policy review batch 4
November Management review, prepare annual planning for the following year
December Close measures, consolidate documentation, surveillance audit (if scheduled)

This calendar is a framework that you must adapt to your specific certification cycle and organizational rhythms. The surveillance audit can fall in any month, and your internal audit should be completed at least two months before the external audit.

Typical Problems in Ongoing Operations and Countermeasures

Problem: The ISM Is Alone

After certification, many organizations reduce ISMS resources to the ISM alone. The ISM is supposed to do everything single-handedly: assess risks, track measures, review policies, organize training, prepare for the audit — and handle their original duties on the side. This does not work.

Countermeasure: Ensure that the roles (risk owners, asset owners) are actively fulfilled even after certification. The ISM coordinates, but the responsibility for substantive work lies with the business departments. If risk owners neglect their duties, executive management must address it.

Problem: Executive Management Loses Interest

The certificate hangs on the wall, customers are satisfied, and executive management has other priorities. The ISMS becomes an annoying mandatory program.

Countermeasure: Keep executive management engaged through regular, brief, and relevant reporting. Do not report on the PDCA cycle but on risks affecting the business, KPIs demonstrating effectiveness, and trends signaling the need for action. Use the management review as an opportunity to discuss strategic topics, not as a document review.

Problem: Measures Are Endlessly Postponed

Measures from the risk assessment or audit are prioritized, scheduled, and then postponed because day-to-day business takes precedence. After two postponements, they are forgotten.

Countermeasure: Define clear escalation rules. Measures postponed once are discussed at the next monthly review. Measures postponed twice are escalated to executive management. This sounds bureaucratic but creates the necessary accountability.

Problem: Changes Are Not Incorporated

The organization introduces a new CRM, adopts a new cloud service, or opens an office in another city. Nobody thinks to update the ISMS: asset register, risk assessment, scope documentation, supplier assessment.

Countermeasure: Integrate an ISMS check into the change management process. With every significant change (new system, new service provider, organizational restructuring), the ISM checks whether the ISMS needs updating. This takes five minutes per change and prevents a backlog from building up.

Problem: Awareness Falls Asleep

The first awareness training was well attended and interesting. The second was a repeat of the first. The third became a mandatory exercise where everyone stared at their phones.

Countermeasure: Vary formats and content. Use current incidents from the press as hooks. Incorporate interactive elements. Bring in guest speakers (an external penetration tester, forensic expert, data protection officer). Keep it short: 30 minutes of focused input beats two hours of lecture-style presentation. And celebrate successes: if the phishing click rate dropped from 25 percent to 8 percent, communicate that.

What the Auditor Wants to See at the Surveillance Audit

At the surveillance audit, the auditor has less time than at the initial certification audit. They will focus on specific areas and go deep there. What they will want to see in every case:

Evidence of continuous activity. Management review minutes, internal audit reports, measure tracking with status updates, updated risk assessments, training records. Everything that shows the ISMS is alive.

Handling of changes. What has changed since the last audit? How was the ISMS adapted? The auditor will specifically ask whether new systems, service providers, or business processes have been incorporated into the risk assessment.

Processing of previous findings. If the initial certification audit or the previous surveillance audit produced findings (minor nonconformities, improvement opportunities), the auditor checks whether they have been addressed. A finding that is still open at the next audit signals a lack of commitment.

Operational evidence. The auditor will not only read documents but also want to see operational evidence: log files showing that monitoring is taking place, vulnerability scan results, incident response activity records, backup restore test results.

The Effort: Planning Realistically

Ongoing ISMS operations require continuous effort. The good news: it is significantly less than the build effort. The bad news: it is not zero.

For a company with 100 to 300 employees, plan for the following annual time budgets:

Activity ISM Effort Business Departments
Maintaining risk assessment 40 to 60 hours 20 to 40 hours
Measure tracking 30 to 50 hours 10 to 20 hours
Policy review 30 to 50 hours 10 to 20 hours
Awareness program 40 to 60 hours 5 to 10 hours per employee
Internal audit 40 to 60 hours 20 to 30 hours
Management review 10 to 15 hours 5 to 10 hours
Ongoing documentation 30 to 50 hours -
Surveillance audit preparation 20 to 30 hours 10 to 15 hours

In total, the ISM effort is 240 to 375 hours per year, or 15 to 25 percent of a full-time position. This is the minimum effort for a well-maintained ISMS. If the ISM additionally takes on operational security tasks (vulnerability management, incident response, supplier assessment), the effort increases accordingly.

From Mandatory Program to Corporate Culture

The ultimate goal is for information security to no longer be a program that the ISM pushes through against organizational resistance but a natural part of how work is done. This does not happen automatically and not quickly. It takes years of consistent effort, visible support from executive management, and the experience that information security is not just burdensome but prevents problems and builds trust.

When an employee does not first search for the policy upon receiving a suspicious email but instinctively contacts IT support — when a project manager asks whether the ISM needs to be involved with a new system — when executive management considers the security implications of an investment decision — then the ISMS has fulfilled its true purpose, regardless of what is written on the certificate.

Further Reading

Keep your ISMS running permanently

ISMS Lite automatically reminds you of due reviews, measures, and audits. ISMS operations become a routine process instead of a forgotten project.

Install now