- ISO family of standards, why use a standardized framework, the ISO:27001 standard and structure, the certification process
- ISO:27001 Clause 4 – ISMS requirements overview, defining the scope, document & record management, minimal documentation requirements
- Defining roles and responsibilities, planning the ISMS implementation project
- Risk management, risk analysis and the statement of applicability (SOA)
- ISO:27001 Clause 5 – Management responsibilities, sample ISO:27001 management awareness training
- ISO:27001 Clause 6 – Internal audits, building an internal audit program
- ISO:27001 Clause 7 – Management reviews, sample agenda
- ISO:27001 Clause 8 – Continuous improvement, root cause analysis, corrective & preventive action plans
- Annex A control objectives (A.5 to A.10)
- Annex A control objectives (A.11 to A.15)
- Other useful standards to ISMS implementation and business improvement, ISO20000/BS25999/PCI-DSS/ISO9001 overview
- Integrating and unifying multiple management systems to prevent redundancy and improve efficiency
Martin Dion (CISSP/CISM)
ISO:27001 Lead Auditor & Trainer
CTO @ Above Security
No comments:
Post a Comment