Module 9: Maintaining the Kingdom

Annual Calendar

Template
20 min
+75 XP

Annual Calendar Template

A well-planned annual calendar is essential for maintaining your ISO 27001 certification without last-minute stress.

Core ISMS Activities

ActivityFrequencyDurationOwner
Management ReviewAnnually2-4 hoursTop Management
Internal AuditAnnually1-5 daysInternal Auditor
Risk Assessment ReviewAnnually1-2 daysRisk Owner
External AuditAnnually1-5 daysAll
Security TrainingOngoingVariesHR/Security
Policy ReviewAnnually2-4 daysPolicy Owner
BC TestingAnnually1 dayBC Coordinator
Access ReviewQuarterly2-4 hoursIT/Security

Sample Calendar Flow

Q1 (Jan-Mar)

  • January: Planning, objectives, training kickoff
  • February: Internal audit prep and execution
  • March: Internal audit completion, management review prep

Q2 (Apr-Jun)

  • April: Management review, risk assessment update
  • May: External audit preparation
  • June: External audit execution, corrective actions

Q3 (Jul-Sep)

  • July: Mid-year review, policy updates
  • August: BC testing
  • September: Access review, third-party assessments

Q4 (Oct-Dec)

  • October: Policy finalization, budget planning
  • November: Document retention review
  • December: Year-end review, next year planning

Monthly Tasks

  • Review security incidents
  • Update incident log
  • Security awareness communication
  • Check backups
  • Review access changes
  • Patch management
  • Monthly metrics

Quarterly Tasks

  • Security metrics review
  • Risk assessment check
  • Corrective action review
  • Access rights review
  • Quarterly management update

Calendar Success Tips

  1. Work backwards from audit date
  2. Avoid peak business periods
  3. Build in buffer time
  4. Assign clear ownership
  5. Set reminders (90/30/7 days)
  6. Review and adjust quarterly

Next Lesson: Keeping documentation fresh and relevant.

Complete this lesson

Earn +75 XP and progress to the next lesson