SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

First steps towards ISO 27001

  Quote
Guest
Guest user Created:   Jul 06, 2020 Last commented:   Jul 06, 2020

First steps towards ISO 27001

We're looking to start the journey towards ISO27001, but we're not sure where to start. As far as I'm aware we need a Gap Analysis to identify the scope of the project, is this something you could assist with?

 

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jul 06, 2020

First is important to note that ISO 27001 does note require gap analysis, and we do not recommend it for small organizations (i.e., up to 100 employees), because due to this size it is easier to go directly to the implementation of the standard.

Broadly speaking, after getting support for your project (through approval of the ISMS project plan) and approval of the Procedure for Document and Record Control, you should consider these steps:

  1. defining ISMS basic framework (e.g., scope, objectives, organizational structure), by understanding the organizational context and requirements of interested parties;
  2. development of risk assessment and treatment methodology;
  3. perform a risk assessment and define the risk treatment plan;
  4. controls implementation (e.g., policies and procedures documentation, acquisitions, etc.);
  5. people training and awareness;
  6. controls operation;
  7. performance monitoring and measurement;
  8. perform an internal audit;
  9. perform management critical review; and
  10. address nonconformities, corrective actions, and opportunities for improvement.

To see how documents compliant with ISO 27001 look like, I suggest you take a look at the free demo of our ISO 27001 Documentation Toolkit at this link: https://advisera.com/27001academy/iso-27001-documentation-toolkit/

This article will provide you a further explanation about ISMS implementation:

These materials will also help you regarding ISO 27001 implementation:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 06, 2020

Jul 06, 2020

Suggested Topics