ISO 27001 · Domain 1
ISMS Planning and Context
About 20% of the exam
The clause map, 4 to 10
- Clause 4
- context, interested parties, scope
- Clause 5
- leadership, policy, roles assigned
- Clause 6
- risk planning, objectives, planned change
- Clause 7
- resources, competence, awareness, documents
- Clause 8
- operate, assess and treat risk
- Clause 9
- monitor, internal audit, management review
- Clause 10
- improvement, nonconformity, corrective action
Clauses 4 to 10 carry the auditable requirements; Annex A is the control reference used inside clause 6.1.3
Clause 4 in four parts
- 4.1
- internal and external issues
- 4.2
- interested parties and their needs
- 4.3
- determine the ISMS scope
- 4.4
- establish, maintain, continually improve
What an ISMS actually is
- Managed system, not a control list
- Covers people, process, technology
- Risk driven, not checklist driven
- Scoped deliberately, boundaries written down
- Improved on a repeating cycle
- Owned and resourced by top management
Build sequence for a new ISMS
- Understand context
- Fix the scope
- Secure leadership commitment
- Assess risk
- Choose treatment and controls
- Write the SoA
- Operate and record
- Audit and review
- Improve
- Trigger
- business need or customer demand
- Typical duration
- six to twelve months
- Gate
- operating evidence before stage 2
- Owner
- top management, delegated day to day
The 27000 family around the standard
- ISO/IEC 27000
- vocabulary and overview
- ISO/IEC 27002
- guidance for the Annex A controls
- ISO/IEC 27003
- implementation guidance
- ISO/IEC 27004
- monitoring, measurement, analysis, evaluation
- ISO/IEC 27005
- information security risk guidance
- ISO/IEC 27006
- rules for certification bodies
- ISO/IEC 27007
- guidance for auditing an ISMS
- ISO/IEC 27008
- assessing individual technical controls
- ISO/IEC 27017
- cloud service control guidance
- ISO/IEC 27018
- personal data in public clouds
- ISO/IEC 27701
- privacy extension to the ISMS
Only 27001 is certifiable; the rest are guidance or scheme rules
Interested parties
- Customers, regulators, staff, suppliers, owners
- Record only the relevant ones
- Capture what each one requires
- Legal duties become ISMS inputs
- Review when the business changes
- Relevance must be arguable, not decorative
Writing the scope
- State boundaries and applicability plainly
- Name locations, services and systems
- Address interfaces and dependencies
- Exclusions need a defensible reason
- Keep it current after change
- Scope drives what auditors sample
Statement of Applicability
- Lists every Annex A control
- Says applicable or excluded
- Gives justification either way
- Records implementation status
- Mandatory documented information
- Updated when treatment decisions change
The SoA is the single document that proves the Annex A comparison happened
PDCA against the clauses
- Plan
- clauses 4, 5, 6 and 7
- Do
- clause 8 operation
- Check
- clause 9 performance evaluation
- Act
- clause 10 improvement
- Cadence
- set by the organization
- Trigger
- planned intervals and significant change
Certification versus compliance
- Compliance
- meeting the requirements yourself
- Certification
- third party audit and certificate
- Issuer
- an accredited certification body
- Not proof of
- zero risk or perfect controls
- Coverage
- only what the certificate names
- Self declaration
- permitted but rarely accepted commercially
Scope and context mistakes
- Scope copied from another company
- Excluding a site to dodge findings
- Interested parties listed without requirements
- Cloud dependencies left outside the boundary
- Scope never revisited after acquisitions
- Interfaces with suppliers left undocumented
- Context issues written once, never reviewed
Documented information, clause 7.5
- 7.5.1
- what the standard and business need
- 7.5.2
- identification, format and review
- 7.5.3
- availability, protection and version control
- Extent
- varies with size and complexity
- External documents
- identified and controlled as well
- Media
- any format counts as documented
What the 2022 edition changed
- Annex A rebuilt into four themes
- Ninety three controls, eleven of them new
- Clause 6.3 added for planned change
- Clause 6.2 objectives must be monitored
- Clause 9.2 and 9.3 split into subclauses
- Clause 10 reordered, improvement stated first
- Preventive action absorbed into risk thinking
- Transition from the 2013 edition has closed
Rapid recall: which clause
- Scope
- clause 4.3
- Policy
- clause 5.2
- Roles
- clause 5.3
- Risk criteria
- clause 6.1.2
- SoA
- clause 6.1.3
- Objectives
- clause 6.2
- Competence
- clause 7.2
- Internal audit
- clause 9.2
- Management review
- clause 9.3
- Corrective action
- clause 10.2
Terms to keep straight
- Requirement
- clauses 4 to 10, mandatory
- Control
- a measure that modifies risk
- Annex A
- reference list of controls
- ISO/IEC 27002
- how to implement those controls
- Documented information
- documents and records together
- Interested party
- can affect or be affected
Reference strip: context, scope, family, cycle, evidence
Context
- Internal and external issues
- Interested parties and their requirements
- Reviewed at planned intervals
Scope
- Boundaries, applicability, interfaces
- Documented information under clause 4.3
- Exclusions justified, never convenient
Family
- 27002 gives implementation guidance
- 27005 gives risk guidance
- 27701 extends to privacy
Cycle
- Plan in clauses 4 to 7
- Do in clause 8
- Check in 9, act in 10
Evidence
- Scope statement and policy
- Risk criteria and the SoA
- Audit and review records
Quick exam traps
- Trap: The ISMS scope must always cover the whole organization
- Trap: A certificate proves every control works perfectly
- Trap: Annex A is a mandatory list every organization must implement
- Trap: An organization can be certified against ISO/IEC 27002
- Trap: Documented information means paper procedures only
- Trap: Context needs reviewing only in the weeks before an audit
- Trap: Leaving a site out of scope keeps it away from the auditor
cybercertprep.com · original revision sheet written from the public body of knowledge