ISO 27001 · Domain 2
Leadership and Support
About 15% of the exam
Clause 5, what leadership must do
- 5.1 Accountability
- top management owns ISMS effectiveness
- 5.1 Integration
- ISMS built into business processes
- 5.1 Resources
- make people, money and tools available
- 5.1 Communication
- stress conformity and its importance
- 5.1 Support
- help other managers lead security
- 5.2 Policy
- documented, communicated, available as needed
- 5.3 Roles
- assigned, communicated, authority stated
Top management is the person or group directing the organization at the highest level; a security manager is not a substitute
Clause 6, planning duties
- 6.1.1
- risks and opportunities for the ISMS
- 6.1.2
- define the risk assessment process
- 6.1.3
- treatment, control comparison and the SoA
- 6.2
- objectives, plans, monitoring and updates
- 6.3
- change the ISMS in planned steps
Clause 6.2 requires objectives to be monitored, so a target with no measure attached is a finding
Policy requirements, 5.2
- Appropriate to the purpose of the organization
- Includes objectives or a framework
- Commits to meeting applicable requirements
- Commits to continual improvement
- Documented, communicated, available where needed
- Available to interested parties as appropriate
- Supported by topic specific policies
Roles and authorities, 5.3
- Assigned by top management
- Communicated inside the organization
- Authority to report ISMS performance
- Authority to confirm conformity to requirements
- Risk owners named, not implied
- Control owners recorded in the SoA
- Job descriptions carry the responsibilities
Objectives that survive audit, 6.2
- Consistent with the security policy
- Measurable where practicable
- Consider requirements and risk results
- Monitored, communicated and updated
- Retained as documented information
- Plan names what, who, when, resources
- Plan says how results are evaluated
Clause 7.1 resources
- Determine what the ISMS needs
- Provide people, budget, tooling, time
- Resource gaps become audit findings
- Reviewed when the scope grows
- Decisions traceable to management review
Clause 7.2 competence
- Define competence needed per role
- Base it on education, training, experience
- Act to close any gap
- Evaluate whether the action worked
- Retain evidence of competence
- Covers contractors doing ISMS work
Clause 7.3 awareness
- Everyone knows the security policy
- Everyone knows their own contribution
- Everyone knows the cost of nonconformity
- Extends to people under organizational control
- Awareness is not the same as competence
Clause 7.4 communication
- On what
- the topics that must be communicated
- When
- the timing or the trigger
- With whom
- internal and external audiences
- Who
- the person who communicates
- How
- the channel actually used
Management review, clause 9.3
- Collect the required inputs
- Convene at planned intervals
- Judge suitability, adequacy, effectiveness
- Decide changes and resources
- Record the outputs
- Track actions to closure
- Status of previous review actions
- Changes in issues and interested parties
- Feedback on information security performance
- Nonconformities and corrective actions
- Monitoring and measurement results
- Audit results and objective fulfillment
- Feedback from interested parties
- Risk assessment results and treatment status
- Opportunities for continual improvement
Review outputs and their proof
- Decisions on continual improvement opportunities
- Decisions on any ISMS changes needed
- Resource decisions recorded with owners
- Minutes retained as documented information
- Actions carried into the next review
- Held at planned intervals, not on demand
- Chaired with authority to commit resources
A review held only when something goes wrong fails clause 9.3.1, however good the discussion was
Leadership and support failures
- Policy signed once, never communicated
- Objectives with no measure attached
- Security manager mistaken for top management
- Competence claimed without any records
- Review delegated to a junior analyst
- Outputs discussed but never recorded
- ISMS changed with no planning step
- Awareness slides offered as competence evidence
Clause 6.3, planned change
- New clause in the 2022 edition
- Changes made in a planned manner
- Consider purpose and possible consequences
- Check resources and responsibilities first
- Applies to scope, structure and technology
Evidence an auditor asks for
- Policy
- approved, dated, communicated version
- Roles
- assignment and communication records
- Objectives
- plan with owners and measures
- Competence
- role requirements and proof held
- Awareness
- delivery and comprehension records
- Communication
- the plan and examples sent
- Review
- minutes with decisions and actions
Reference strip: leadership, planning, support, review, proof
Leadership
- Accountable for ISMS effectiveness
- Policy issued and communicated
- Roles assigned with authority
Planning
- Risks and opportunities determined
- Objectives measurable and monitored
- Change handled under clause 6.3
Support
- Resources determined and provided
- Competence defined and evidenced
- Awareness, communication, documented information
Review
- Nine listed inputs considered
- Improvement and change decisions
- Planned intervals, minutes retained
Proof
- Signed policy and role letters
- Objective plans with measures
- Training records and review minutes
Quick exam traps
- Trap: The information security manager counts as top management
- Trap: A published policy is enough without communicating it
- Trap: Security objectives do not need to be measurable at all
- Trap: Attendance at awareness training proves competence
- Trap: Management review can be held whenever an issue arises
- Trap: Review outputs need no record if the same people attend
- Trap: Clause 6.3 only applies to changes in technology
cybercertprep.com · original revision sheet written from the public body of knowledge