Here's a diagram that covers common steps to an ISO 27001 readiness and implementation. Put simply, it's a lot of work. One area that should not be difficult, is the thing people often fear the most, the implementation of system policy via security controls.


Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics