An information security management system must be established for ISO 27001. The scope of certification has to be clearly defined. Relevant processes and responsibilities must be identified. Information security risks need to be assessed. The ISO 27001 requirements must be fulfilled within the defined scope.