ISMS Tools in Practice (2)
Supporting ISMS Operations with Dedicated Tools
When setting up an ISMS, the question often arises where and with which tools the information generated and required in the process should be documented and maintained. ISMS tools primarily focus on mapping the requirements of one or more standards into a data model. The actual operational tasks of an ISMS and their support are often not at the core of these tools. This article examines the tasks that should be supported by an ISMS tool and the functionalities required to support the selection, procurement, or development of such tools.
By Knut Haufe, Berlin
Building on the pitfalls and success factors as well as the process reference model for operating an ISMS (compatible with IT-Grundschutz) based on ISO/IEC TS 27022:2021, the following sections describe, process by process, which functions an ISMS tool should provide to support both ISO/IEC 27001 and the BSI IT-Grundschutz.
This overview can be used both as a checklist for selecting a suitable ISMS tool and for comparative analyses of current ISMS tools.
With regard to the processes shown in Table 1, a distinction is made between:
Tool-specific administrative processes Processes for administering the ISMS tool itself or its technical interfaces to other tools.
Method-dependent base processes Processes or elements of a standard-specific methodology – such as BSI Standard 200-2 or ISO/IEC 27001.
ISMS operational processes Based on ISO/IEC 27001, BSI IT-Grundschutz, and the ISMS process reference model of ISO/IEC TS 27022.
(Table 1: ISMS tool processes at a glance – omitted here as it is an image reference.)
The following sections describe, process by process, how and with which functions an ISMS tool should support each process.
Role and Permission Management
The objective is to ensure the need-to-know principle for processed data as well as operational capability within and with the ISMS tool.
Supported activities:
Creating, editing, and locking users and roles
Permission control at the level of information networks, objects, or specific functions
Integration with directory services (e.g. Active Directory, SSO)
Role-based workflows and dashboards
Logging of all access to data objects including timestamps and user information
Basis: BSI IT-Grundschutz, module ORP.4, requirements A3 and A12 (“Identity and Access Management”).
Master Data Management
Objective: Representation of multiple versions and catalogues of requirements, controls, and risks.
Import of catalogues
Structured import of catalogues for requirements, controls, and risks
Parallel use of different versions (BSI Compendium, ISO Annex A)
Change management
A transition workflow supports changes to catalogues:
New requirement → To-do list entry with rule-based deadlines
Requirement removed → Option to “retain and transform into own requirement” or delete
Requirement unchanged → No action
Requirement wording changed → Automatic processing within the transition workflow
Basis: BSI IT-Grundschutz Compendium, ISO/IEC 27001 Annex A, and further controls where applicable.
Asset / Structure Analysis
Objective: Complete and standard-compliant documentation of assets as a foundation for all subsequent ISMS processes.
Recording of assets, scopes, and networks
Preconfigured mandatory and optional fields
Assignment of assets to scopes/networks
Nesting of scopes/networks
Unified data model (one asset, multiple views)
Documentation of scope boundaries
Import and interfaces
One-time or regular/automated imports
Standardised interfaces
Workflow-driven completion of missing data
Customising and grouping
Definition of custom asset attributes
Workflow for grouping elements
Assistant-supported group maintenance
Basis: BSI 200-2, sections 3.3.4 and 8.1, ISO/IEC 27001:2022 Annex A, Table A.1, control 5.9 in conjunction with section 6.1.3 c.
Requirements Management / Determination of Protection Needs
Objective: Document the protection requirements (confidentiality, integrity, availability) for each asset.
Supported activities:
Customisable protection need categories
Planning and conducting interviews (e.g. via Teams invitations)
Audit trail for every field and change
Dashboard for the Information Security Officer (ISO/ISB) for quality control
Automatic inheritance of protection needs including documentation of deviations
Automatic re-inheritance when changes occur
Regular reviews of protection needs via workflow
Structured management of requirements (source, owner, responsibilities, internal/external, fulfilment approach, etc.)
Basis: BSI 200-2 section 8.2, BSI Compendium ISMS.1.A2, A6, A9–A11, ISO/IEC 27001:2022 sections 4.2, 5.1.b, 6.2.c, and 8.1.
Modelling / Statement of Applicability (SoA)
Objective: Derive and document all necessary and appropriate risk treatment measures.
Supported activities:
Modelling automation based on BSI rules
Adaptable and additional modules/controls
Workflows for modelling in outsourcing scenarios
Automatic creation of the Statement of Applicability
Documentation of reasons for inclusion and exclusion
Basis: BSI 200-2 section 8.3, ISO/IEC 27001:2022 section 6.1.3 d.
IT-Grundschutz Check / Gap Analysis
Planning
Role-based dashboards
Scheduling and resubmission
Automatic assignment of responsible persons
Use of references (similar to BSI GSTOOL)
Documentation
Status, dispensability, interview data
Rule-based mandatory fields
Verification and review planning
Ability to break down into sub-requirements
Triggers for follow-up processes
“no” / “partially” → creation of temporary risk
“dispensable” → mandatory justification, no risk acceptance possible for basic requirements
Basis: BSI 200-2 section 8.4.
Risk Analyses
Supported steps:
Automatic selection of relevant target objects
Pre-population using modules/controls, protection needs, and IT-Grundschutz check results
Standard-compliant risk analysis fields
Documentation of risk owners
Temporary risk acceptance with automatic review
Dashboards for risk owners
Risk maps and reporting to overarching risk management
Basis: BSI 200-2 section 8.5, BSI 200-3, ISO/IEC 27001:2022 sections 6.1.2 and 6.1.3.
Stakeholder and Requirements Management
Objective: Achieve a complete and accurate understanding of stakeholder expectations regarding the ISMS and target security level.
Supported activities:
Structured documentation of stakeholders (as data entities) and their requirements
Attribute assignment (internal/external owner, legal/contractual, business goal, priority, impact of non-compliance, etc.)
Grouping and linking of similar/conflicting requirements
Automatic generation of risks from requirements
Reporting for internal and external context
Assessment and assignment of responsibilities
Resolving goal conflicts through prioritisation (with resulting risk creation)
Basis: BSI 200-2 section 3.2.1, BSI 200-1 sections 3.2.1 and 7.1, ISO/IEC 27001:2022 sections 4.2, 5.1.b, 6.2.c and 8.1.
Initiation and Tracking of Measure Implementation
Objective: Ensure implementation of the risk treatment plan and all associated changes.
Planning
Bundling measures into measure packages or projects
Defining sequence, deadlines, and responsibilities
Documenting and evaluating costs and effort
Documenting dependencies
Traceability back to requirements and risks
Initiation & tracking
Communication of responsibilities via workflow (ticket or email integration)
Linking measures to project plans, protocols, and status reports
Documenting status and last review date
Automatic to-do generation for implementation verification
Automatic update of IT-Grundschutz check entries upon confirmation of implementation
Automatic creation of temporary risks for measures with future implementation dates (“today + x”)
Basis: BSI Compendium ISMS.1.A7, A10, A11; BSI 200-2 sections 6.4 and 9.x; ISO/IEC 27001:2022 section 8.1.
Incident Management
Objective: Identification, reporting, assessment, and treatment of information security incidents as well as learning from them.
Supported activities:
Recording incidents from upstream systems (helpdesk, etc.) or via manual input
Prioritisation, categorisation, and classification using configurable schemes
Documentation of impact and details including text, links, and uploaded evidence
Automatic communication and escalation depending on classification (e.g. to IT, DPO, emergency management)
Triggering reassessment or creation of new risks via workflow
Basis: BSI Compendium DER.1, DER.2.1, DER.2.3; ISO/IEC 27001:2022 Annex A, Table 1, control 16 in conjunction with section 6.1.3 c.
Internal Audits
Planning of internal audits (audit programme)
Tool-supported management of audit programmes
Automatic and configurable planning of the audit programme
Documentation of criteria, objectives, scope, lead auditors
Risk-based selection using configurable parameters (time horizon, scope, confidence level, etc.)
Consideration of BSI/ISO/IAF rules (e.g. effort calculation, onsite vs. offsite)
Automatic breakdown into audit plans with manual adjustment options
Execution of audits
Workflows, checklists, and questionnaires
Scheduling of audit steps
Central storage of reference documents, evidence, checklists, and plans
Automated communication (reminders, upload options for audited parties)
Management of training and competence records for auditors
Automatic report generation
Enforcement of prerequisites before audit execution (mandatory trainings, declarations, etc.)
Configurable categories of findings; documentation of root causes and corrective actions
Audit follow-ups
Workflows and to-do lists for tracking deviations
Scheduling of follow-up audits
Basis: BSI Compendium DER.3.1; BSI 200-2 section 10.1; ISO/IEC 27001:2022 section 9.2.
Policies and Governing Documents
Objective: Ensure that all relevant information security requirements are documented, complete, and traceable.
Supported activities:
Mapping requirements to policies and governing documents (both at requirement/measure level and granular regulation level)
Document lifecycle management via workflow (review, resubmission, scheduling, ownership, approvals, co-signatures)
Attribute management for each regulation (responsible party, owner, target audience, source, topic, etc.)
Assistance in drafting regulations using a consistent language model
Individual generation of policy documents from atomic rules (e.g. “create a policy for target group X on topic Y”)
Searchable frontend for all employees
Basis: BSI 200-2 section 5.2; ISO/IEC 27001:2022 section 7.5.3.
Contract and Service Provider Management
Objective: Avoid negative security impacts arising from outsourced services.
Supported activities:
Structured documentation of external service providers, services, and associated security concepts (link to modelling/SoA process)
Workflows for applying BSI outsourcing modelling rules
Integration with procurement databases and systems via interfaces
Workflows integrated into procurement for security review of planned purchases
Planning and execution of service provider audits (integration with internal audit process)
Evaluation of service providers from a security perspective (integration with KPI/dashboard process)
Basis: BSI “IT-Grundschutz methodology in the context of outsourcing”; ISO/IEC 27001:2022 section 8.1.
Awareness and Training
Objective: Ensure ongoing awareness and appropriate competence in information security for all persons involved in information processing.
Supported activities:
Assessing awareness levels via questionnaires and evaluations
Planning and executing training, awareness, and further education measures
Assigning measures to employee groups and tracking completion
Documentation of who completed which measure when and with what result
Generating and storing attendance lists for in-person events
Storing and managing training and awareness materials
Integration with calendars and collaboration tools (e.g. MS Teams)
Feedback workflows for continuous improvement of measures
Basis: BSI Compendium ORP.3; BSI 200-2 sections 4.4, 4.5, 9.5; ISO/IEC 27001:2022 sections 7.2 and 7.3.
Reporting and Communication
Objective: Provide decision-makers and stakeholders with appropriate information on information security risks, costs of measures, maturity levels, target achievement, incidents, and more.
Supported activities:
Automatic generation of A.x reference documents (BSI) and Statements of Applicability (SoA) per scope/view
Predefined and configurable reports integrated into relevant ISMS processes (report generator)
(Semi-)automated workflows and communication plans for time-controlled generation and distribution of reports
Documentation of what is reported to whom, how often, and in which form
Basis: BSI Compendium ISMS.1.A6; BSI 200-2 section 5.2.4; ISO/IEC 27001:2022 section 7.4.
Performance Management / KPI Dashboard
Objective: Continuous evaluation of security measures and ISMS performance against objectives and requirements.
Supported activities:
Definition and linking of KPIs for effectiveness and efficiency of ISMS processes and measures
Automatic calculation of KPIs based on ISMS tool data
Configurable, role-based dashboards with metrics, trends, charts, and reporting options
Thresholds and alert rules that trigger automatic notifications
Basis: BSI Compendium ISMS.1.A1; BSI 200-2 section 10.1; ISO/IEC 27001:2022 section 9.1.
Resource Management
Objective: Ensure that adequate resources for the ISMS and security measures are available and used efficiently.
Supported activities:
Planning required resources and breaking down available/budgeted resources for measures and ISMS operations (integrated with the measure implementation process)
Monitoring resource usage and generating configurable resource utilisation reports
Basis: BSI 200-2 section 9; ISO/IEC 27001:2022 sections 6.2 and 7.1.
Continuous Improvement (CIP)
Objective: Ensure ongoing optimisation of the efficiency and effectiveness of the ISMS.
Supported activities:
Root cause analysis for deviations (from performance management and internal audits)
Deriving, documenting, and initiating improvement measures via workflow
Automatic import of recommendations from internal or external audits as improvement potentials
Structured documentation, evaluation, and decision-making for improvement ideas
Support for triggers such as environmental changes, new technologies, innovations, and employee suggestions
Suggestion function for all employees (optionally anonymous) with workflow and automated feedback on processing status
Basis: BSI 200-2 section 10; ISO/IEC 27001:2022 sections 10.1 and 10.2.
Change Management
Objective: Avoid negative effects of changes on the information security level.
Supported activities:
Control of changes to documented ISMS elements (assets, protection needs, risks, catalogues, etc.) via workflows and transition processes that consider logical dependencies and prompt follow-up steps (e.g. new protection needs, inheritance checks, risk analyses)
Workflows for assessing and approving/rejecting changes triggered outside the ISMS tool (via interfaces)
Documented risk assessments of planned changes and feedback to the originating system
Basis: BSI 200-2 sections 5.2 and 10.2; BSI Compendium OPS.1.1.3; ISO/IEC 27001:2022 sections 8.1 and 10.2.
Management of Records and Evidence
Objectives: Ensure availability, correct identification, description, formatting, review, approval, and protection of all records required to demonstrate the effectiveness of the ISMS.
Supported activities:
Structured storage of records and evidence with a configurable permission model
Search and retrieval functions for required records
Storage of records either within the ISMS tool database or via external links
Workflows for deleting records after configurable retention periods have expired
Basis: BSI 200-2 section 5; BSI Compendium ISMS.1.A13; ISO/IEC 27001:2022 section 7.5.
Conclusion
The described operational tasks that should be supported by an ISMS tool can be used in three ways:
Organisations that are building and operating an ISMS can use the described functions as a basis for selecting or tendering ISMS tools.
Organisations that plan, develop, or have already developed an ISMS tool can use the described functions as a generic requirements set and benchmark their current tools against it.
The functional and requirements set described can be condensed and applied in market analyses of current ISMS tools.
Author: Prof. Dr. Knut Haufe, Director Cyber-Security Services, EY Consulting GmbH.

fuentis Team
Team
The fuentis team brings together specialists in information security, data protection and risk management — supporting organizations with reliable, audit-ready solutions.



