Skip to main content

Legacy ISMS Migration Plan

Source Inventory Reviewed

The local ../legacy folder in core12-it-repos is currently empty. The usable legacy source set was found at /Users/taheny/repos/core12-it-fu-X/ISMS_Backup and duplicate OneDrive export paths.

Primary Source Choice

SourceDecision
General/Policies/Core 12 - Security Policy v1.8/Core 12 Security Policy - v1.8.docxPrimary ISMS policy basis. Most recent located version: revision 329, modified 2026-01-26.
ISA_Submit/1.1.1/CORE 12 LLC - SECURITY POLICY_v1.6.docxOlder submitted copy. Keep only as audit history, not as the migration basis.
General/Templates/Core 12 Agreements/Core 12 Employee Agreement.docxEmployee agreement source ported in full.
ISA_Submit/1.2.2/Core 12 Employee Agreement.docxSubmitted duplicate; same internal metadata as template copy.

Migration to core12-isms-management

Legacy source areaUse in management repoTarget issue/register
Information Management Log spreadsheetSeed live registers and review due datesAssets, IT Services, Websites, Web Apps, Desktop Apps, Licences, Risks
IT Services reviews: Azure, Jira, Office 365Create service records with owner, MFA/SSO, supplier review, contract, RTO/RPOregister:itservices issues
Managed device reviews and disposal recordsCreate hardware/storage records, disposal evidence, inactive-device review tasksregister:assets issues
Client and digital project reviewsCreate client service/project records and website/web application recordsregister:websites, register:webapps, register:itservices
Third party vendor reviews and agreementsCreate vendor records with DPA/security review dates and agreement evidenceregister:personnel with personnel:vendor, or add a dedicated vendor register if preferred
Employee policy review forms and agreementsLink signed acknowledgements to personnel recordsregister:personnel employee issues
Termination checklistsAttach or summarize completion evidence on closed personnel recordsregister:personnel review/termination issues
Facility access reviewsTrack as facility/access review evidence and risksPersonnel review, asset review, or new facility review issue type
IT security training certificatesTrack annual training completion by person and campaignPersonnel review issues; optional training campaign issue
IT weekly touchbase notes and quarterly IT reviewsUse as management-review and continual-improvement evidenceMonthly summary / management review issue
BCP DR plans and tabletop exercisesCreate BCP records and annual tabletop review tasksIT service review, risk review, and BCP tabletop issues
Security incident checklist/templatePreserve as incident/PIR workflowregister:incidents issues
Risk Register referenceSeed initial risk backlogregister:risks issues
Unauthorized Software referenceSeed approved/blocked desktop application recordsregister:desktopapps issues
Data Protection Measures referenceUse as checklist text in service/app/vendor review templatesIT service, app, website, vendor review issues
Vendor agreement clausesUse as required vendor/security review checklistVendor and IT service issue templates

First 10 Migration Actions

  1. Add register:documents, migration:legacy-isms, and control:gap labels to core12-isms-management.
  2. Create a document-review issue for every Markdown document in this repo.
  3. Create service records for Microsoft 365, Azure, Jira, GitHub, Cloudflare, Jamf/Jamf Protect, Microsoft Defender, hosting providers, and backup/file-storage services.
  4. Create personnel records for active employees and contractors, linking signed agreements and annual policy reviews.
  5. Create vendor records for every third party with access to Core 12 or client data.
  6. Create web application and website records for active client and internal digital properties.
  7. Create initial risks from the Risk Register Seed List.
  8. Create BCP review tasks for ransomware, power outage, cloud service outage, and office inaccessibility scenarios.
  9. Convert termination/onboarding templates into personnel issue checklists or linked evidence records.
  10. Configure review reminder automation to open review issues in the management repo.

Open Gaps

  • The local core12-it-repos/legacy directory should either be populated with the selected legacy source set or replaced by a README pointing to the canonical archive location.
  • Management repo currently has strong register templates but no document-review or migration-task template. Add those next.
  • The existing management monthly summary reports empty registers; seed records are needed before summaries become useful.