First steps towards ISO 27001
We're looking to start the journey towards ISO27001, but we're not sure where to start. As far as I'm aware we need a Gap Analysis to identify the scope of the project, is this something you could assist with?
Assign topic to the user
First is important to note that ISO 27001 does note require gap analysis, and we do not recommend it for small organizations (i.e., up to 100 employees), because due to this size it is easier to go directly to the implementation of the standard.
Broadly speaking, after getting support for your project (through approval of the ISMS project plan) and approval of the Procedure for Document and Record Control, you should consider these steps:
- defining ISMS basic framework (e.g., scope, objectives, organizational structure), by understanding the organizational context and requirements of interested parties;
- development of risk assessment and treatment methodology;
- perform a risk assessment and define the risk treatment plan;
- controls implementation (e.g., policies and procedures documentation, acquisitions, etc.);
- people training and awareness;
- controls operation;
- performance monitoring and measurement;
- perform an internal audit;
- perform management critical review; and
- address nonconformities, corrective actions, and opportunities for improvement.
To see how documents compliant with ISO 27001 look like, I suggest you take a look at the free demo of our ISO 27001 Documentation Toolkit at this link: https://advisera.com/27001academy/iso-27001-documentation-toolkit/
This article will provide you a further explanation about ISMS implementation:
- ISO 27001 implementation checklist https://advisera.com/27001academy/knowledgebase/iso-27001-implementation-checklist/
These materials will also help you regarding ISO 27001 implementation:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- ISO 27001 Foundations Course at this link: https://advisera.com/training/iso-27001-foundations-course/
Comment as guest or Sign in
Jul 06, 2020