Zum Hauptinhalt springen

Create and edit a technical and organizational measure

Technical and organizational measures (TOMs) are the documented security concept of your ISMS. This guide shows how to create a TOM document, maintain the master data in the "General" section, fill the measure categories with text modules, and define the association with organizations.

Last updated:

A TOM document describes the technical and organizational measures you actually use to protect your systems and information. Within an ISMS it is the evidence that belongs to the requirements in your requirement catalogue: the catalogue names the requirement, the TOM document describes the implemented measure. This guide shows how to create a TOM and maintain its three central areas — master data, measure categories and association.

Prerequisites

  • You are logged into a team that uses the “Technical and organizational measures” module.
  • You have permission to create and edit technical and organizational measures. The “Published” status additionally requires the permission to publish.
  • You have access to the associated organization, or the document is shared for “All organisations”.

Step by step

  1. In the left menu under “Collateral securities”, click “Technical and organizational measures”.
  2. Click the arrow icon next to the “New” button in the top right and select “Create technical and organisational measures” for an empty document, “Load from sample documents” for a prepopulated template, “Upload file” for a security concept that already exists as a Word or PDF file, or “Create linked document” for a derived variant of a subsidiary organization.
  3. Maintain the master data in the “General” section: “Designation” as a mandatory field, the “Status” (“New”, “In progress”, “Published” or “Archived”), an optional custom “Document ID” such as ISMS-TOM-001, and the “Description” as a formatted long text.
  4. In the “Association” section, define the scope the document applies to: enter the name of an organization in the “Organisations” field and select it from the suggestion list, or activate “All organisations” if the TOM is to apply to all organizations in your team.
  5. Fill in the measure categories in the sections “Ensuring confidentiality” (the three access control categories and “Separation control measures”), “Ensuring integrity” (“Disclosure control” and “Input monitoring”), “Pseudonymization and encryption”, “Ensuring availability, resilience and recoverability”, and “Procedures for regular review, assessment and evaluation”.
  6. To do so, click in the input field of a category and select an existing text module from the suggestions. Use the plus icon to the right of the field to create, edit or duplicate text modules; use the X icon to remove an assigned module from the category again. Change the order using the move icon.
  7. Check the result with the “Preview” button in the top right, then click “Save”. The arrow icon next to “Save” may offer “Save and publish”.

Editing later

Open the detail page of the TOM document and click “Edit” in the top right, or “Edit” in the “Actions” selection menu. As long as the document is in the “Published” status, set it back to “In progress” before changing its content; when it moves to “Published” again, a new revision is created automatically. If the TOM was created via “Upload file”, a separate section for replacing the file appears instead of the measure categories.

Practical tip

Maintain only a few clearly formulated text modules per category — typically three to eight — instead of recording every individual measure as its own entry. Lists of 30 mini-measures look like a checklist in an audit rather than an effective security concept and regularly lead to follow-up questions about whether the measures have actually been implemented. Because the modules are reusable across the team, the wording stays consistent across all locations — a frequent review point in ISO/IEC 27001 certification audits, where the measures serve as evidence for the Annex A controls.

Changes and errors may occur. The information in this article has been carefully compiled, but does not claim to be complete or correct.

Related glossary terms