August 2024
Intermediate to advanced
123 pages
2h 15m
English
ISO 27001 is a specification for an information security management system, so unsurprisingly, it sets out requirements for a management framework. The fourth step in the ISMS implementation is to create that framework.
Clause 4 of ISO 27001 says the organisation must understand the needs and expectations of interested parties, as well as the internal context of the organisation, and that these should be considered when establishing the scope of the ISMS.
You should have started to identify these requirements when creating your project risk register, so you can use this opportunity to revisit and build upon that information. The external context will include the business and risk environment, what’s going on in ...
Read now
Unlock full access