Information security management system (ISMS)

A management system that is actually lived

Project support for the implementation of a holistic information security management system. We support your internal information security officer or take on the entire implementation project.

  • Certified Experts and Specialized lawyers
  • For every size of company – from start-ups to conglomerates
ISO 9001
BvD member
GDD member
Made in Germany
20 years of experience
  • Federal Office for Information Security
  • Compliant with GDPR
  • BvD member
  • GDD member
  • Made in Germany
✓ Interdisciplinary team ✓ certified experts ✓ pragmatic implementation
Basics

What is information security management?

Asmus Eggert

Asmus Eggert

Signature Asmus Eggert

CEO & Attorney at Law, mip Consult GmbH

The digital threat landscape and ever-growing regulatory requirements present enormous challenges for companies. It is no longer enough to simply respond to incidents. Instead, proactive, systematic security management is required that meets legal requirements, closes technical vulnerabilities, and ensures the trust of customers and partners.

our approach

This is how we build your ISMS

Please do not hesitate to contact us.

Step 01

Free initial consultation

We offer a free initial telephone consultation to discuss with you the current state of information security in your company.

Step 02

Needs analysis

Together, we understand the current state, risks, and goals, both technically and organizationally.

Step 03

Customized offer

Based on your current situation and the coordinated approach, we will create an offer that is tailored directly to your needs.

Step 04

Start of consulting

After signing the consulting contract, our information security experts will begin the consulting process.

Step 01

Free initial consultation

We offer a free initial telephone consultation to discuss with you the current state of information security in your company.

Step 02

Needs analysis

Together, we understand the current state, risks, and goals – both technically and organizationally. Often, an advanced information security checkup is useful to assess the current situation.

Step 03

Customized offer

Based on your current situation and the coordinated approach, we will create an offer that is tailored directly to your needs.

Step 04

Start of consulting

After signing the consulting agreement, our information security experts begin the consulting process – usually with a kick-off meeting including a presentation of all the participants.

Asmus Eggert, CEO and lawyer of mip Consult GmbH
Asmus Eggert · CEO & Attorney

From the location determination
until certification maturity
.

Non-binding · 15 minutes · Free

Frequently asked questions

What is an ISMS?

An information security management system is the organizational framework with which you can permanently control information security: policies, processes, responsibilities, and controls. Unlike technical data protection management, which, under Art. 32 GDPR, only considers personal data, an ISMS covers all data, all processing processes, and all processing systems, regardless of whether they involve personal data.


Do we need to be ISO 27001 certified?

Certification is not legally required. However, it is the established proof that your measures comply with the state of the art, and this is exactly what § 30 BSIG requires from affected facilities. In dealings with customers and in tenders, it is often the easier argument than any self-declaration.


ISO 27001 or BSI IT-Grundschutz – what is the difference?

Both are not mutually exclusive. The BSI offers certification to ISO 27001 based on IT basic protection: a separate scheme with a much more concrete list of measures. The pure ISO certification gives you more leeway in choosing the measures; IT basic protection takes away more of the decision-making power. Which path is right for you depends on your industry and your clients.

Which version of ISO 27001 applies?

ISO/IEC 27001:2022. The transition period for the 2013 version expired on October 31, 2025; certificates issued after that date under the old version are invalid. Anyone who missed the transition must undergo a new certification today instead of a Delta audit.


How does the ISMS differ from data protection management?

The legally required technical data protection measures protect not only personal data, but in principle other company data to the same extent. There is a certain overlap between the two. The difference lies in the perspective: Data protection focuses on the rights of the affected individuals, while information security focuses on the availability, integrity, and confidentiality of your systems.


Can sofortdatenschutz.de support me with any questions about information security?

Our experts in data protection and information security are happy to assist you in implementing technical and organizational measures or in establishing a holistic information security management system (ISMS).

Other services

Information security services,
that suits your company.