Expert Advice Community

Guest

Fast implementation project

  Quote
Guest
Guest user Created:   Sep 19, 2017 Last commented:   Sep 19, 2017

Fast implementation project

I would like to know how to handle Clients who want a Management System established and certified within a very short period (say 3 months). How do you allocate time for training, documentation, implementation, internal audit, management review and finally, certification?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Sep 19, 2017

Answer: First of all, you have to identify if it is possible to implement and certificate the management system in such short period. Some organizations may already have another systems implemented, or culture that can make the implementation easier, or the certification scope is small, but for others you will have to start from scratch. And in all these cases you have to count with management support in terms of money and human resources.
What I can say to you is that if you have to start from scratch it will be very unlikely to accomplish implementation and certification in such a small period, most because the quantity of documents to be developed and the time needed to perform all activities that are prescribed by the documentation.

To have an idea about how much time you would need, I suggestion to take a look at our ISO 27001/ISO 22301 Implementation Duration Calculator at this link: https://advisera.com/27001academy/free-tools/free-calculator-duration-of-iso-27001-iso-22301-implementation/

Regarding time allocation, if you identify the three month period (tweelve weeks) is enough for the implementation, this is a good estimation of phases duration:

Weeks 1-2: Project planning and elaboration of basic management system documentation (e.g., ISMS scope, information security policy, procedure for documentation control, procedure for internal audit, procedure for risk assessment and treatment, etc.)
Week 2-3: Carrying out the risk assessment and risk treatment plan elaboration
Week 4-5: Information security policies and procedures elaboration
Weeks 5-8 : Implementation, operation and evaluation of policies and procedures (at this point some corrective actions may be required)
Week 9: Internal audit and management review
Week 10-12: Treatment of internal audit nonconformities and management review decisions

Since this is a short period, the selection of the certification body should be performed in parallel to these activities, starting at the beginning of the project.

This article will provide you further explanation about ISO 27001 implementation:
- How long does it take to implement ISO 27001 / BS 25999? https://advisera.com/27001academy/blog/2011/11/08/how-long-does-it-take-to-implement-iso-27001-bs-25999/

These materials will also help you regarding about ISO 27001 implementation:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Sep 19, 2017

Sep 19, 2017

Suggested Topics