Expert Advice Community

Guest

Implementation steps

  Quote
Guest
Guest user Created:   Jul 26, 2017 Last commented:   Jul 26, 2017

Implementation steps

We prepare the mandatory documentation required by the standard, do documentation review whether policies are implemented and now we have risk assessment and risk treatment plan. My question is what is the next step after this
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jul 26, 2017

Answer: For ISO 27001 implementation, after the risk treatment plan you should consider:

- Definition on how to measure the effectiveness of controls
- Implement the controls & mandatory procedures (not only documentation, but also technical and physical controls)
- Implement training and awareness programs
- Operate and monitor the system
- Perform internal audit and management review
- Implement corrective and preventive actions as needed

This article will provide you further explanation about implementation steps:
- ISO 27001 implementation checklist https://advisera.com/27001academy/knowledgebase/iso-27001-implementation-checklist/

These materials will also help you regarding implementation steps:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 26, 2017

Jul 26, 2017

Suggested Topics

Guest user Created:   Aug 24, 2019 ISO 27001 & 22301
Replies: 1
0 0

Implementation steps

Guest user Created:   Feb 28, 2018 ISO 27001 & 22301
Replies: 1
0 0

Implementation steps