Information security affects almost every area of a company today. Processes, IT systems, and employees are closely interconnected, and so are the risks. An Information Security Management System (ISMS) based on ISO 27001 provides the framework to systematically manage these risks.
Anyone ISO 27001 looking to implement needs more than just policies and documents. Risks must be assessed, responsibilities clarified, and incidents handled in a structured manner. Furthermore, the system should be subject to continuous improvement. This works best when information security is anchored where the actual work happens: in the business processes.
This is exactly the approach taken by our BPM & GRC software, Aeneis. The ISMS functions in Aeneis are bundled into a dedicated app and linked with processes, roles, and IT systems. The following eight building blocks show what is essential for implementation and how Aeneis supports you at every step.

1. Management Commitment
A ISMS stands or falls with the leadership team. They provide resources, set goals, and make information security visible throughout the company. For this to succeed, responsibilities must be clear from the very beginning.
By implementing your ISMS in our BPM & GRC software, Aeneis, you can model the organizational context of your ISMS. You can document who is involved and in what capacity, and visualize the ISMS organization as a diagram from management and information security officers down to the ISMS team. Dashboards and heatmaps show the status of risks before and after mitigation at a glance. This provides management with an overview of documented risks and their assessments.
2. Information Security Policies
The information security policy is the foundation of an ISMS. It defines how information should be protected and provides employees with binding guidelines. However, it only becomes effective when everyone involved is familiar with it and can apply it in their daily work.
In Aeneis, you can centrally document ISMS goals and policies and make them available to the entire company as well as to individual branches. Information is provided centrally, with access based on assigned permissions. For each legal entity, you can store ISMS manuals, for example regarding the context of the organization, interested parties, and the scope. You can customize the included ISMS manual using SmartEdit or replace it with your own documents.
3. Processes and Procedures
ISO 27001 requires documented and active procedures that are regularly reviewed. Equally important is the scope according to Chapter 4.3: Companies must define the boundaries of their ISMS.
This is where the process-oriented approach of Aeneis shows its strength. You determine whether a process is relevant to information security directly within the process itself. In the scope area, you define for each legal entity which processes the ISMS should protect. An analysis lists all processes marked as ISMS-relevant, allowing you to quickly see if descriptions and labels align.
Responsibilities also remain closely tied to the process. With the RACI matrix in Aeneis, you can record who is responsible, accountable, consulted, or informed in security-critical workflows.
4. Risk Assessment and Management
The systematic assessment of security risks is the heart of ISO 27001. Risks must be identified, assessed, and prioritized. You then determine how to handle each risk.
In Aeneis, you go through three steps:
1. Risk identification: You determine the ISMS relevance of your processes, assess their protection requirements, and link the IT systems used. By default, processes, IT systems, and employees are counted as assets.
2. Risk analysis: You assess the criticality of an IT system based on confidentiality, integrity, availability, and authenticity. You create risks for the asset and evaluate their impact and probability of occurrence.
3. Risk treatment: Risks in the medium and high risk categories are added to the treatment plan. There, you assign measures, evaluate the net risk, and decide whether to accept, treat, avoid, or transfer the risk.
You don't have to start from scratch. The master data contains catalogs of threats, vulnerabilities, risk scenarios, and ISO 27001 controls. In addition, ISMS risks are integrated into central corporate risk management. Anyone already maintaining their IT systems in i-doit can connect them to Aeneis via a partner interface.
5. Training and Awareness
Technology alone does not protect information. Employees must be aware of risks and know how they can contribute to security themselves. Regular training and awareness-raising are therefore an integral part of an ISMS.
Aeneis involves employees directly in the ISMS. You assign them roles and delegate tasks for implementing measures. Those involved complete these ISMS tasks via the task dashboard . You can also derive targeted training topics from reported incidents. This way, awareness-raising is based on real events rather than theory.
6. Security Incident Management
Despite all precautions, security incidents can still occur. The crucial thing is that they are detected, investigated, and resolved quickly.
In Aeneis you can report information security incidents via a quick-access portal and manage them centrally. You document every incident, assess it, and initiate the response. Similar incidents and affected objects can be linked directly. In the overview of all reported incidents, you can identify security gaps and training needs, gaining insights for the further development of your ISMS.
7. Internal Audits
Internal audits verify whether the ISMS is effective and meets the requirements of the standard. They also highlight where there is room for improvement. When it comes to preparation, one thing matters most: that evidence is complete and quickly available.
A key document is the Statement of Applicability (SoA). In Aeneis, you assess whether the controls from Annex A are applicable for each legal entity. For every control, you can record an explanation, link implementation documents, track the implementation status, and assign measures.
All documentation and evidence can be exported with just a few clicks. From Aeneis, you can generate printed reports such as the SoA report, export tables as Excel files, and save documents as PDFs. Additionally, Aeneis offers a dedicated audit management app.
8. Continuous Improvement
An ISMS is not a one-time project. Threats and business requirements change, and the system must evolve accordingly.
In Aeneis, you can view the current status of your risks and their assessments at any time. Reports such as the risk register, the risk matrix with Gross and net assessment and the action overview show where action is required. You can implement insights from incidents and audits directly as new ISMS tasks and assign them to the responsible parties. This makes improvement a fixed part of your daily work routine.
Conclusion: Implementing ISO 27001 in a process-oriented way with Aeneis
An effective ISMS is not created by documents alone. What matters is that information security is integrated into the organization and its processes: with clear responsibilities, assessed risks, structured incident management, and continuous improvement.
Aeneis maps all of this on a single platform. ISMS-relevant processes, IT systems, and employees are directly linked to risks, measures, and evidence. You can find more about the features on the page ISMS in Aeneis and in the article Implementing ISO 27001 digitally and securely.
Would you like to build your ISO 27001-compliant ISMS with Aeneis? Request a trial version or schedule a personal Live demo with the Aeneis team.
Frequently asked questions about implementing ISO 27001
What does it mean to implement ISO 27001?
Implementing ISO 27001 means establishing, operating, and continuously improving an ISMS in accordance with the standard's requirements. This includes, among other things, the scope, risk assessment and treatment, the Statement of Applicability, internal audits, and management review. You can find an overview on our Information Security Management System with Aeneis page.
What is the Statement of Applicability (SoA)?
The Statement of Applicability is a mandatory document under ISO 27001. It specifies for each of the 93 controls from Annex A of the 2022 version whether it is applicable and why. In Aeneis, you manage the SoA for each legal entity, including implementation status and linked evidence.
How does Aeneis support risk assessment according to ISO 27001?
Aeneis guides you through risk management in three steps: identification, analysis, and treatment. IT systems are evaluated based on confidentiality, integrity, availability, and authenticity, with risks assessed both before and after mitigation measures. Catalogs of threats, vulnerabilities, and ISO 27001 controls make it easy to get started.
Can I define the scope separately for multiple companies?
Yes. In the ISMS app, you determine the scope for each legal entity separately. You also maintain the Statement of Applicability and ISMS manuals for each legal entity individually.




