Skip to main content

c. What are the Major Steps of Establishing and Implementing ISMS to ISO/IEC 27001?

ISO/IEC 27001 provides a model for establishing, implementing, maintaining and continually improving an ISMS:

  1. Define the scope, boundary and policy of ISMS

  2. Define the risk assessment approcah of the organisation

  3. Identify and evaluate risk and options for the relevant treatment

  4. Select appropriate control objectives and controls for the treatment for risks

  5. Obtain management approval of the proposed residual risks

  6. Obtain management authorisation to implement and operate the ISMS

  7. Monitor, review, maintain and improve the ISMS continuously

Back