A TickIT strategy

I have a basic knowledge of the TickIT scheme. But can anyone give me an overall strategy for applying it. I believe it goes something like this..
Get Management on-side
Document procedures and processes
Identify shortcomings
Fix them
Run an internal assesment
Get the boys in
keep doing it cause the'll spot check you.

Is this anywhere near??
