Skip to content
Amrani Academy

5. Putting it into practice

Workplace scenarios

An ISMS is tested in small moments, not grand ones. For each scenario, decide what you would do before reading on.

Scenario 1: The borrowed login

A contractor starting today cannot get into the project system because his account is not ready. His deadline is tight, and a colleague suggests he works under her login until IT sorts it out.

What good looks like: nobody works under anyone else's credentials, however reasonable the deadline. Shared logins destroy accountability and breach the access control policy, and an auditor sampling access records could treat it as a nonconformity. The right route is to chase the access request with IT, and to flag the slow starter process as a weakness so it gets fixed for the next joiner.

Scenario 2: The propped-open door

Walking back from lunch, you find the door to the server room wedged open with a fire extinguisher. Contractors have been carrying equipment in and out all morning, and propping the door saved them badging through on every trip.

What good looks like: close the door, or stay by it, and report what you found to the security manager or facilities. This is both a physical security weakness and a live gap in the secure areas control. Reporting it is not telling tales on the contractors; it lets the organisation arrange proper supervised access, and it is exactly the reporting behaviour a healthy ISMS depends on.

Scenario 3: The handy free tool

Your team is drowning in file requests, and a teammate sets up a free file-sharing account over the weekend, then shares client folders into it. It works brilliantly, and nobody outside the team knows it exists.

What good looks like: raise it with your manager or the security manager rather than quietly joining in. The account now holds company information that nobody is risk assessing, backing up, or protecting: classic shadow IT. The fix is usually process, not punishment: request a proper tool through the approved route, migrate the data, and close the unofficial account.

Scenario 4: The auditor's question

During a surveillance audit, an external auditor stops at your desk and asks how you would report a lost work phone. You know there is a procedure, but you cannot remember the exact steps.

What good looks like: answer honestly. Say you would report it straight away, and that you would check the incident reporting page on the intranet or call the helpdesk for the exact route. Do not guess, and do not describe an ideal process you have never used. Knowing where to look is a good answer; a confident invention is a bad one, and honest answers are what keep audit evidence trustworthy.

Course contents