A family of standards that define how organisations manage and protect information through an ISMS.
In short:
ISO 27001 = what you must do to build an ISMS
ISO 27002 = how to do it
Clauses 1-3 (Scope, Normative References, Terms) are introductory.
Scenario: A small private clinic stores patient records in a cloud system and has 20 staff.
Task: List one internal factor and one external factor that would influence the ISMS for this clinic
Senior management must:
The clinic is starting its ISMS project and needs visible support from senior management to ensure staff take the process seriously.
Example actions:
These actions show real leadership commitment, which is essential for the ISMS to be accepted and followed across the organisation.
The clinic needs to plan how it will manage risks within its new ISMS.
These steps ensure the organisation has a clear and structured plan for treating risks and choosing appropriate controls.
All controles are in Annex A
Attributes help organisations categorise controls and map them to frameworks (e.g. NIST CSF, CIS Controls).
Each control in ISO/IEC 27002:2022 is described using these attributes.
Information exists in different states → each requires specific security controls
Data/information must be protected in all states
Short ISO-Quiz
Please review you lab and activities from here
Right: image
- Set clear and measurable **security objectives**
- **CIS Controls** (operational categories)
