ISMS at an Infrastructure Operator

Design, Implementation, and Evolution of an ISMS

As per requirements, an ISMS based on ISO 27001 had to be established within 24 months and implemented in approximately 170 organizational units for over 200 IT applications. Between 2024 and 2025, around 218 prioritized IT applications were integrated, and maturity level 3 of the group’s internal capability model was achieved. We supported the approach model, governance, and roll-out, and subsequently managed the strategic integration of an additional 78 IT applications into the ISMS of the group management.

Challenge

Initial Situation: According to the requirements, an ISMS based on ISO 27001 had to be developed within the client organization and implemented in approximately 170 organizational units for over 200 IT applications within 24 months. Between 2024 and 2025, around 218 prioritized IT applications were integrated, and maturity level 3 of the group’s internal capability model was achieved.

Problem: At the outset, the maturity level of procedural, organizational, and technological governance requirements was low, and a systematic implementation concept was lacking. After the initial roll-out, an additional 250 IT applications were not yet integrated, while regulatory requirements and IS risks continued to rise, demanding high management attention.

Need: A systematic implementation plan, strategic and operational support for the introduction and further development, and the integration of an additional 78 applications into the ISMS of the group management were required to further enhance cyber defense capabilities.

Approach

1

Recording of client-specific requirements

2

Development, presentation, coordination, and approval of a systematic approach model for ISMS implementation

3

Determination of required personnel and budgetary resources, and support for the internal approval process

4

Support in developing procedural, organizational, and technological requirements, and creating an IS policy

5

Support in developing suitable competence formats for application owners

6

Support for approximately 170 organizational units in implementing requirements at operational and strategic levels

Result

A time-based and content-driven roll-out plan, including resource estimation, has been developed, coordinated, and approved

Governance requirements have been developed and are bindingly anchored within group management

Competence formats have been developed, introduced, and are continuously being refined

ISMS requirements are being successively implemented in the organizational units according to the roll-out plan

The maturity level of the ISMS is demonstrably and continuously improving

Required management levels and committees are involved

"Such rapid progress in the development and implementation of the ISMS would not have been possible without the consulting firm."

Areas of Application

This project is relevant for corporate groups and conglomerates that need to establish an ISMS based on ISO 27001 group-wide and expand it to other applications after an initial roll-out. The approach is particularly relevant for many decentralized organizational units, tight deadlines, low governance maturity, increasing regulatory pressure, and high management attention. It combines conception, governance, resource and competence building with strategic and operational roll-out control.

Further Project Examples