ISO 27002 5a. Prepare Statement of Applicability 1. Get management support
0. Start here
2. Define ISMS scope
Business case
4. Conduct information security risk assessment
3. Inventory information assets
5b. Prepare Risk Treatment Plan
RTP
ISMS scope 6. Develop ISMS implementation program
Inventory
9. ISMS operational artifacts
Project plan
N
Policies Report Security logs etc.
SOA
Standards Procedures
8. Information Security Management System
One project within the program
Report Awareness & Report training attendance & test reports etc.
Project plan
7. ISMS implementation program
Guidelines Report Compliance & audit reports etc.
Project plan
N-1
PDCA cycle (one of many) 10. Compliance review
11. Corrective actions Key
12. Precertification assessment
Version 2 May 2007 Copyright © 2007 IsecT Ltd. www.ISO27001security.com
ISO 27001
13. Certification audit
ISO 27001 certificate
14. Party party
Activity
Database
Document or output
ISO standard