Skip to content
Roadmap templates

Roadmap — Zero Trust and ISO/IEC 27001 Certification

A security roadmap for a fictional insurer moving to zero trust and certifying to ISO/IEC 27001:2022 within the year, with the Stage 1 and Stage 2 audits as milestones: 15 items (5 done, 3 in progress, 6 planned, 1 at risk) and 2 milestones across five lanes, status date 7 Jul 2027. All 14 dependencies finish before their dependents start — the internal audit and the 93-control Statement of Applicability before Stage 1 — and the longest chain runs from the risk assessment to closing audit nonconformities. Illustrative roadmap.

Template previewRoadmap
Orbisure — security roadmap 2027Orbisure — security roadmap 2027Zero-trust controls and ISO/IEC 27001:2022 certification in one planDone 5In progress 3Planned 6At risk 12 milestones14 dependenciesStatus date 7 Jul 2027LANES · QUARTER2027Q1Q2Q3Q4MILESTONESToday · 7 Jul 2027Identity3 itemsDevices2 itemsNetwork2 items · 1 at riskDetection andresponse2 itemsGovernance andcertification6 itemsPhishing-resistant MFA (FIDO2) for all staff · (Q1) · doneJust-in-time privileged access · (Q2 .. Q3) · in progress · 55%Automated quarterly access reviews · (Q4) · plannedEDR on every laptop and server · (Q1) · doneDevice posture in conditional access · (Q2) · doneZTNA replaces the VPN for 1,800 staff · (Q2 .. Q3) · at risk · owner Network teamMicro-segmentation of the claims platform · (Q4) · plannedSIEM migration and 24×7 MDR · (2027-03 .. 2027-07) · in progress · 80%IR playbooks and tabletop exercise · (2027-08 .. 2027-09) · plannedRisk assessment and SoA (93 Annex A controls) · (Q1) · donePolicy set and awareness training · (2027-04 .. 2027-08) · in progress · 70%Internal audit and management review · (2027-08) · plannedClose audit nonconformities · (2027-11-23 .. 2027-12-22) · plannedBusiness continuity test · (2027-10) · plannedTop-40 supplier security assessments · (2027-03 .. 2027-06) · doneISO 27001 Stage 1 audit · (2027-09-15) · milestone, plannedStage 2 certification audit · (2027-11-22) · milestone, plannedPhishing-resistant MFA(FIDO2) for all staffJust-in-time privileged access · 55%Automated quarterlyaccess reviewsEDR on every laptop andserverDevice posture inconditional accessZTNA replaces the VPN for 1,800 staffNetwork teamMicro-segmentation of theclaims platformSIEM migration and 24×7 MDR · 80%IR playbooks and tabletop exerciseRisk assessment and SoA(93 Annex A controls)Policy set and awareness training · 70%Internal audit and management reviewClose audit nonconformitiesBusiness continuity testTop-40 supplier security assessmentsISO 27001 Stage 1 auditStage 2 certification auditCHECKS15 items in 5 lanes and 2 milestones: 5 done, 3 in progress, 6 planned, 1 at risk — every dependency finishes before its dependent starts.1 item at risk: “ZTNA replaces the VPN for 1,800 staff”.Longest dependency chain: “Risk assessment and SoA (93 Annex A controls)” → “Policy set and awareness training” → “ISO 27001 Stage 1 audit” → “Stage 2 certification audit”→ “Close audit nonconformities” (5 steps, ending 22 Dec 2027).All 14 dependencies finish before their dependents start.Nothing is past its date and unfinished as of 7 Jul 2027.Illustrative example: Orbisure is a fictional insurer; headcounts, controls and dates are invented and are not audit advice.

Make it your own.

title "Orbisure — security roadmap 2027"
subtitle "Zero-trust controls and ISO/IEC 27001:2022 certification in one plan"
note "Illustrative example: Orbisure is a fictional insurer; headcounts, controls and dates are invented and are not audit advice."
axis quarters 2027-Q1 .. 2027-Q4
today 2027-07-07

milestone stage1 "ISO 27001 Stage 1 audit" 2027-09-15 planned after audit, policies
milestone stage2 "Stage 2 certification audit" 2027-11-22 planned after stage1, playbooks

lane "Identity" color: indigo
  item mfa "Phishing-resistant MFA (FIDO2) for all staff" Q1 done
  item pam "Just-in-time privileged access" Q2 .. Q3 in progress 55% after mfa
  item reviews "Automated quarterly access reviews" Q4 planned after pam

lane "Devices" color: sky
  item edr "EDR on every laptop and server" Q1 done
  item posture "Device posture in conditional access" Q2 done after edr

lane "Network" color: teal
  item ztna "ZTNA replaces the VPN for 1,800 staff" Q2 .. Q3 at risk after mfa owner: "Network team"
  item segment "Micro-segmentation of the claims platform" Q4 planned after ztna

lane "Detection and response" color: rose
  item siem "SIEM migration and 24×7 MDR" 2027-03 .. 2027-07 in progress 80%
  item playbooks "IR playbooks and tabletop exercise" 2027-08 .. 2027-09 planned after siem

lane "Governance and certification" color: violet
  item soa "Risk assessment and SoA (93 Annex A controls)" Q1 done
  item policies "Policy set and awareness training" 2027-04 .. 2027-08 in progress 70% after soa
  item audit "Internal audit and management review" 2027-08 planned after soa
  item nc "Close audit nonconformities" 2027-11-23 .. 2027-12-22 planned after stage2
  item bcp "Business continuity test" 2027-10 planned after stage1
  item supplier "Top-40 supplier security assessments" 2027-03 .. 2027-06 done