Overview
ISO/IEC 27001 specifies requirements for an information security management system. It applies risk management to people, processes, technology and information assets, supported by a justified Statement of Applicability.
Business benefits
- Structured management of information-security risks
- Improved protection of confidential, integral and available information
- Clear security roles and accountability
- Stronger customer and contractual confidence
- More disciplined incident, supplier and continuity controls
Key assessment focus
01
ISMS scope and risk methodology
02
Risk assessment and treatment plan
03
Statement of Applicability
04
Security objectives and operational controls
05
Monitoring, incidents and continual improvement
Typical information required
- ISMS scope and interested-party requirements
- Risk assessment and treatment records
- Statement of Applicability
- Policies, procedures and control evidence
- Internal audit, management review and corrective actions
Certification process
Application
Scope, sites, employees, shifts and process details.
Stage 1
Readiness, system design and audit planning review.
Stage 2
Evaluation of implementation and effectiveness.
Decision
Independent review followed by surveillance planning.
Frequently asked questions
No. Any organization handling important information can implement an ISMS, including healthcare, finance, manufacturing, education and public services.
It identifies applicable information-security controls, explains inclusion or exclusion and records implementation status.
Yes. Cloud-hosted infrastructure and supplier controls should be addressed according to the defined ISMS scope and risks.