Clarify evidence goal and information domain
First, we clarify which evidence is required: an attestation for Basic Protection, an ISO 27001 certification on the basis of IT-Grundschutz, or an IS audit without a certificate. We then define the boundaries of the information domain – sites, processes, systems and service providers.
For an initial review, a one- to two-day workshop with your subject-matter contacts is often enough.
Your evidence goal
A clearly bounded information domain and a defined evidence goal as the basis for effort and project plan.


