Skip to main content
ISMS

ISMS Tools in Practice: Requirements & Functions for Effective ISMS Operations

Which functions should an ISMS tool provide to support operations? This article examines process-specific requirements from administration to continuous improvement, covering ISO 27001 and BSI IT-Grundschutz standards.

fuentis Team

fuentis Team

Team

ISMS Tools in Practice: Requirements & Functions for Effective ISMS Operations

ISMS Tools in Practice (2)

Supporting ISMS Operations with Dedicated Tools

When setting up an ISMS, the question often arises where and with which tools the information generated and required in the process should be documented and maintained. ISMS tools primarily focus on mapping the requirements of one or more standards into a data model. The actual operational tasks of an ISMS and their support are often not at the core of these tools. This article examines the tasks that should be supported by an ISMS tool and the functionalities required to support the selection, procurement, or development of such tools.

By Knut Haufe, Berlin

Building on the pitfalls and success factors as well as the process reference model for operating an ISMS (compatible with IT-Grundschutz) based on ISO/IEC TS 27022:2021, the following sections describe, process by process, which functions an ISMS tool should provide to support both ISO/IEC 27001 and the BSI IT-Grundschutz.

This overview can be used both as a checklist for selecting a suitable ISMS tool and for comparative analyses of current ISMS tools.

With regard to the processes shown in Table 1, a distinction is made between:

  1. Tool-specific administrative processes Processes for administering the ISMS tool itself or its technical interfaces to other tools.

  2. Method-dependent base processes Processes or elements of a standard-specific methodology – such as BSI Standard 200-2 or ISO/IEC 27001.

  3. ISMS operational processes Based on ISO/IEC 27001, BSI IT-Grundschutz, and the ISMS process reference model of ISO/IEC TS 27022.

(Table 1: ISMS tool processes at a glance – omitted here as it is an image reference.)

The following sections describe, process by process, how and with which functions an ISMS tool should support each process.


Role and Permission Management

The objective is to ensure the need-to-know principle for processed data as well as operational capability within and with the ISMS tool.

Supported activities:

  • Creating, editing, and locking users and roles

  • Permission control at the level of information networks, objects, or specific functions

  • Integration with directory services (e.g. Active Directory, SSO)

  • Role-based workflows and dashboards

  • Logging of all access to data objects including timestamps and user information

Basis: BSI IT-Grundschutz, module ORP.4, requirements A3 and A12 (“Identity and Access Management”).


Master Data Management

Objective: Representation of multiple versions and catalogues of requirements, controls, and risks.

Import of catalogues

  • Structured import of catalogues for requirements, controls, and risks

  • Parallel use of different versions (BSI Compendium, ISO Annex A)

Change management

A transition workflow supports changes to catalogues:

  • New requirement → To-do list entry with rule-based deadlines

  • Requirement removed → Option to “retain and transform into own requirement” or delete

  • Requirement unchanged → No action

  • Requirement wording changed → Automatic processing within the transition workflow

Basis: BSI IT-Grundschutz Compendium, ISO/IEC 27001 Annex A, and further controls where applicable.


Asset / Structure Analysis

Objective: Complete and standard-compliant documentation of assets as a foundation for all subsequent ISMS processes.

Recording of assets, scopes, and networks

  • Preconfigured mandatory and optional fields

  • Assignment of assets to scopes/networks

  • Nesting of scopes/networks

  • Unified data model (one asset, multiple views)

  • Documentation of scope boundaries

Import and interfaces

  • One-time or regular/automated imports

  • Standardised interfaces

  • Workflow-driven completion of missing data

Customising and grouping

  • Definition of custom asset attributes

  • Workflow for grouping elements

  • Assistant-supported group maintenance

Basis: BSI 200-2, sections 3.3.4 and 8.1, ISO/IEC 27001:2022 Annex A, Table A.1, control 5.9 in conjunction with section 6.1.3 c.


Requirements Management / Determination of Protection Needs

Objective: Document the protection requirements (confidentiality, integrity, availability) for each asset.

Supported activities:

  • Customisable protection need categories

  • Planning and conducting interviews (e.g. via Teams invitations)

  • Audit trail for every field and change

  • Dashboard for the Information Security Officer (ISO/ISB) for quality control

  • Automatic inheritance of protection needs including documentation of deviations

  • Automatic re-inheritance when changes occur

  • Regular reviews of protection needs via workflow

  • Structured management of requirements (source, owner, responsibilities, internal/external, fulfilment approach, etc.)

Basis: BSI 200-2 section 8.2, BSI Compendium ISMS.1.A2, A6, A9–A11, ISO/IEC 27001:2022 sections 4.2, 5.1.b, 6.2.c, and 8.1.


Modelling / Statement of Applicability (SoA)

Objective: Derive and document all necessary and appropriate risk treatment measures.

Supported activities:

  • Modelling automation based on BSI rules

  • Adaptable and additional modules/controls

  • Workflows for modelling in outsourcing scenarios

  • Automatic creation of the Statement of Applicability

  • Documentation of reasons for inclusion and exclusion

Basis: BSI 200-2 section 8.3, ISO/IEC 27001:2022 section 6.1.3 d.


IT-Grundschutz Check / Gap Analysis

Planning

  • Role-based dashboards

  • Scheduling and resubmission

  • Automatic assignment of responsible persons

  • Use of references (similar to BSI GSTOOL)

Documentation

  • Status, dispensability, interview data

  • Rule-based mandatory fields

  • Verification and review planning

  • Ability to break down into sub-requirements

Triggers for follow-up processes

  • “no” / “partially” → creation of temporary risk

  • “dispensable” → mandatory justification, no risk acceptance possible for basic requirements

Basis: BSI 200-2 section 8.4.


Risk Analyses

Supported steps:

  • Automatic selection of relevant target objects

  • Pre-population using modules/controls, protection needs, and IT-Grundschutz check results

  • Standard-compliant risk analysis fields

  • Documentation of risk owners

  • Temporary risk acceptance with automatic review

  • Dashboards for risk owners

  • Risk maps and reporting to overarching risk management

Basis: BSI 200-2 section 8.5, BSI 200-3, ISO/IEC 27001:2022 sections 6.1.2 and 6.1.3.


Stakeholder and Requirements Management

Objective: Achieve a complete and accurate understanding of stakeholder expectations regarding the ISMS and target security level.

Supported activities:

  • Structured documentation of stakeholders (as data entities) and their requirements

  • Attribute assignment (internal/external owner, legal/contractual, business goal, priority, impact of non-compliance, etc.)

  • Grouping and linking of similar/conflicting requirements

  • Automatic generation of risks from requirements

  • Reporting for internal and external context

  • Assessment and assignment of responsibilities

  • Resolving goal conflicts through prioritisation (with resulting risk creation)

Basis: BSI 200-2 section 3.2.1, BSI 200-1 sections 3.2.1 and 7.1, ISO/IEC 27001:2022 sections 4.2, 5.1.b, 6.2.c and 8.1.


Initiation and Tracking of Measure Implementation

Objective: Ensure implementation of the risk treatment plan and all associated changes.

Planning

  • Bundling measures into measure packages or projects

  • Defining sequence, deadlines, and responsibilities

  • Documenting and evaluating costs and effort

  • Documenting dependencies

  • Traceability back to requirements and risks

Initiation & tracking

  • Communication of responsibilities via workflow (ticket or email integration)

  • Linking measures to project plans, protocols, and status reports

  • Documenting status and last review date

  • Automatic to-do generation for implementation verification

  • Automatic update of IT-Grundschutz check entries upon confirmation of implementation

  • Automatic creation of temporary risks for measures with future implementation dates (“today + x”)

Basis: BSI Compendium ISMS.1.A7, A10, A11; BSI 200-2 sections 6.4 and 9.x; ISO/IEC 27001:2022 section 8.1.


Incident Management

Objective: Identification, reporting, assessment, and treatment of information security incidents as well as learning from them.

Supported activities:

  • Recording incidents from upstream systems (helpdesk, etc.) or via manual input

  • Prioritisation, categorisation, and classification using configurable schemes

  • Documentation of impact and details including text, links, and uploaded evidence

  • Automatic communication and escalation depending on classification (e.g. to IT, DPO, emergency management)

  • Triggering reassessment or creation of new risks via workflow

Basis: BSI Compendium DER.1, DER.2.1, DER.2.3; ISO/IEC 27001:2022 Annex A, Table 1, control 16 in conjunction with section 6.1.3 c.


Internal Audits

Planning of internal audits (audit programme)

  • Tool-supported management of audit programmes

  • Automatic and configurable planning of the audit programme

  • Documentation of criteria, objectives, scope, lead auditors

  • Risk-based selection using configurable parameters (time horizon, scope, confidence level, etc.)

  • Consideration of BSI/ISO/IAF rules (e.g. effort calculation, onsite vs. offsite)

  • Automatic breakdown into audit plans with manual adjustment options

Execution of audits

  • Workflows, checklists, and questionnaires

  • Scheduling of audit steps

  • Central storage of reference documents, evidence, checklists, and plans

  • Automated communication (reminders, upload options for audited parties)

  • Management of training and competence records for auditors

  • Automatic report generation

  • Enforcement of prerequisites before audit execution (mandatory trainings, declarations, etc.)

  • Configurable categories of findings; documentation of root causes and corrective actions

Audit follow-ups

  • Workflows and to-do lists for tracking deviations

  • Scheduling of follow-up audits

Basis: BSI Compendium DER.3.1; BSI 200-2 section 10.1; ISO/IEC 27001:2022 section 9.2.


Policies and Governing Documents

Objective: Ensure that all relevant information security requirements are documented, complete, and traceable.

Supported activities:

  • Mapping requirements to policies and governing documents (both at requirement/measure level and granular regulation level)

  • Document lifecycle management via workflow (review, resubmission, scheduling, ownership, approvals, co-signatures)

  • Attribute management for each regulation (responsible party, owner, target audience, source, topic, etc.)

  • Assistance in drafting regulations using a consistent language model

  • Individual generation of policy documents from atomic rules (e.g. “create a policy for target group X on topic Y”)

  • Searchable frontend for all employees

Basis: BSI 200-2 section 5.2; ISO/IEC 27001:2022 section 7.5.3.


Contract and Service Provider Management

Objective: Avoid negative security impacts arising from outsourced services.

Supported activities:

  • Structured documentation of external service providers, services, and associated security concepts (link to modelling/SoA process)

  • Workflows for applying BSI outsourcing modelling rules

  • Integration with procurement databases and systems via interfaces

  • Workflows integrated into procurement for security review of planned purchases

  • Planning and execution of service provider audits (integration with internal audit process)

  • Evaluation of service providers from a security perspective (integration with KPI/dashboard process)

Basis: BSI “IT-Grundschutz methodology in the context of outsourcing”; ISO/IEC 27001:2022 section 8.1.


Awareness and Training

Objective: Ensure ongoing awareness and appropriate competence in information security for all persons involved in information processing.

Supported activities:

  • Assessing awareness levels via questionnaires and evaluations

  • Planning and executing training, awareness, and further education measures

  • Assigning measures to employee groups and tracking completion

  • Documentation of who completed which measure when and with what result

  • Generating and storing attendance lists for in-person events

  • Storing and managing training and awareness materials

  • Integration with calendars and collaboration tools (e.g. MS Teams)

  • Feedback workflows for continuous improvement of measures

Basis: BSI Compendium ORP.3; BSI 200-2 sections 4.4, 4.5, 9.5; ISO/IEC 27001:2022 sections 7.2 and 7.3.


Reporting and Communication

Objective: Provide decision-makers and stakeholders with appropriate information on information security risks, costs of measures, maturity levels, target achievement, incidents, and more.

Supported activities:

  • Automatic generation of A.x reference documents (BSI) and Statements of Applicability (SoA) per scope/view

  • Predefined and configurable reports integrated into relevant ISMS processes (report generator)

  • (Semi-)automated workflows and communication plans for time-controlled generation and distribution of reports

  • Documentation of what is reported to whom, how often, and in which form

Basis: BSI Compendium ISMS.1.A6; BSI 200-2 section 5.2.4; ISO/IEC 27001:2022 section 7.4.


Performance Management / KPI Dashboard

Objective: Continuous evaluation of security measures and ISMS performance against objectives and requirements.

Supported activities:

  • Definition and linking of KPIs for effectiveness and efficiency of ISMS processes and measures

  • Automatic calculation of KPIs based on ISMS tool data

  • Configurable, role-based dashboards with metrics, trends, charts, and reporting options

  • Thresholds and alert rules that trigger automatic notifications

Basis: BSI Compendium ISMS.1.A1; BSI 200-2 section 10.1; ISO/IEC 27001:2022 section 9.1.


Resource Management

Objective: Ensure that adequate resources for the ISMS and security measures are available and used efficiently.

Supported activities:

  • Planning required resources and breaking down available/budgeted resources for measures and ISMS operations (integrated with the measure implementation process)

  • Monitoring resource usage and generating configurable resource utilisation reports

Basis: BSI 200-2 section 9; ISO/IEC 27001:2022 sections 6.2 and 7.1.


Continuous Improvement (CIP)

Objective: Ensure ongoing optimisation of the efficiency and effectiveness of the ISMS.

Supported activities:

  • Root cause analysis for deviations (from performance management and internal audits)

  • Deriving, documenting, and initiating improvement measures via workflow

  • Automatic import of recommendations from internal or external audits as improvement potentials

  • Structured documentation, evaluation, and decision-making for improvement ideas

  • Support for triggers such as environmental changes, new technologies, innovations, and employee suggestions

  • Suggestion function for all employees (optionally anonymous) with workflow and automated feedback on processing status

Basis: BSI 200-2 section 10; ISO/IEC 27001:2022 sections 10.1 and 10.2.


Change Management

Objective: Avoid negative effects of changes on the information security level.

Supported activities:

  • Control of changes to documented ISMS elements (assets, protection needs, risks, catalogues, etc.) via workflows and transition processes that consider logical dependencies and prompt follow-up steps (e.g. new protection needs, inheritance checks, risk analyses)

  • Workflows for assessing and approving/rejecting changes triggered outside the ISMS tool (via interfaces)

  • Documented risk assessments of planned changes and feedback to the originating system

Basis: BSI 200-2 sections 5.2 and 10.2; BSI Compendium OPS.1.1.3; ISO/IEC 27001:2022 sections 8.1 and 10.2.


Management of Records and Evidence

Objectives: Ensure availability, correct identification, description, formatting, review, approval, and protection of all records required to demonstrate the effectiveness of the ISMS.

Supported activities:

  • Structured storage of records and evidence with a configurable permission model

  • Search and retrieval functions for required records

  • Storage of records either within the ISMS tool database or via external links

  • Workflows for deleting records after configurable retention periods have expired

Basis: BSI 200-2 section 5; BSI Compendium ISMS.1.A13; ISO/IEC 27001:2022 section 7.5.


Conclusion

The described operational tasks that should be supported by an ISMS tool can be used in three ways:

  • Organisations that are building and operating an ISMS can use the described functions as a basis for selecting or tendering ISMS tools.

  • Organisations that plan, develop, or have already developed an ISMS tool can use the described functions as a generic requirements set and benchmark their current tools against it.

  • The functional and requirements set described can be condensed and applied in market analyses of current ISMS tools.

Author: Prof. Dr. Knut Haufe, Director Cyber-Security Services, EY Consulting GmbH.

fuentis Team

fuentis Team

Team

The fuentis team brings together specialists in information security, data protection and risk management — supporting organizations with reliable, audit-ready solutions.

From reading to doing: your ISMS with fuentis

ISO 27001, BSI IT-Grundschutz, TISAX and NIS2 in one platform – the free/Basic plan is €0 for 12 months.