Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

This section should also cover ISO 27001 chapter 10: Improvement


A guide how to establish and implement an ISMS and the run of your ISMS (the CISO's planning for the year)

The CISO should make his own plan, than implement it in the company, than check internal (f.i. business) external (f.i. law) changes, and than check compliance and to make a plan for the next year to implement findings of the evaluation.  

Establish an ISMS

what's needed to be planned is; 

  • what will be done
  • what resources will be required
  • who will be responsible
  • when it will be completed
  • how the results will be evaluated (art. 6.2 of ISO. 27.001)

Implement an ISMS


Run your ISMS


Evaluate your ISMS

what's needed to be planned; 

  • Make a risk register
  • Make a risk inventory 
  • Make sure that you have an asset inventory
  • Risk assessments
  • Make sure you have a Risk Treatment
  • Awareness training
  • Plan a security training
  • Plan to make policies
  • Check compliance with policies
    • Reviewing
    • Auditing