Clause 4.1 · Context of the organization
Understanding the organization and its context
Identify the internal and external conditions that can shape the ISMS, then keep that view current as the organization and its environment change.
Read the full guide →Clause 4.2 · Context of the organization
Understanding the needs and expectations of interested parties
Determine who can affect, or is affected by, the ISMS and identify which of their legal, contractual, regulatory or business expectations need to be managed.
Read the full guide →Clause 4.3 · Context of the organization
Determining the scope of the information security management system
Define and document the organizational and operational boundaries within which the ISMS is managed and assessed.
Read the full guide →Clause 4.4 · Context of the organization
Information security management system
Establish, operate and continually improve an integrated management system that connects governance, risk, controls, assurance and improvement.
Read the full guide →Clause 5.1 · Leadership
Leadership and commitment
Top management must actively direct and support the ISMS so information security becomes part of business priorities, resources and decisions.
Read the full guide →Clause 5.2 · Leadership
Policy
Set an approved information-security direction that fits the organization and gives a stable basis for objectives and day-to-day decisions.
Read the full guide →Clause 5.3 · Leadership
Organizational roles, responsibilities and authorities
Allocate and communicate who owns ISMS work, who can make decisions and how performance is reported to management.
Read the full guide →Clause 6.1 · Planning
Actions to address risks and opportunities
Plan the ISMS response to uncertainty by connecting organizational context, security risk and improvement opportunities to controlled action.
Read the full guide →Clause 6.1.1 · Planning
General
Decide how the ISMS will address relevant risks and opportunities so it can achieve intended outcomes, reduce unwanted effects and improve.
Read the full guide →Clause 6.1.2 · Planning
Information security risk assessment
Define and apply a repeatable method for identifying, analysing and evaluating information-security risks so results remain reasonably consistent over time.
Read the full guide →Clause 6.1.3 · Planning
Information security risk treatment
Define how evaluated risks will be modified, retained, avoided or shared, select necessary controls and document the resulting treatment decisions.
Read the full guide →Clause 6.2 · Planning
Information security objectives and planning to achieve them
Translate policy and business priorities into clear security outcomes with ownership, resources, measures and delivery plans.
Read the full guide →Clause 6.3 · Planning
Planning of changes
Plan material ISMS changes deliberately so responsibilities, resources, dependencies and unintended effects are understood before implementation.
Read the full guide →Clause 7.1 · Support
Resources
Provide the people, time, technology, information and budget needed to establish, operate and improve the ISMS.
Read the full guide →Clause 7.2 · Support
Competence
Ensure people performing work that affects information-security performance can demonstrate the knowledge, skill and judgement their roles require.
Read the full guide →Clause 7.3 · Support
Awareness
Make sure personnel understand relevant security expectations, their contribution and the consequences of ignoring agreed requirements.
Read the full guide →Clause 7.4 · Support
Communication
Plan what ISMS information must be communicated, when, by whom, to whom and through which reliable channel.
Read the full guide →Clause 7.5 · Support
Documented information
Maintain the information the ISMS needs to operate and the records needed to demonstrate that work was performed and decisions were made.
Read the full guide →Clause 7.5.1 · Support
General
Determine the documented information needed by the standard and by the organization for an effective, usable ISMS.
Read the full guide →Clause 7.5.2 · Support
Creating and updating
Create and revise ISMS information so it is identifiable, suitable for its audience and appropriately reviewed before use.
Read the full guide →Clause 7.5.3 · Support
Control of documented information
Protect and manage documented information throughout its lifecycle so authorized users can find reliable content when needed.
Read the full guide →Clause 8.1 · Operation
Operational planning and control
Translate ISMS plans into controlled day-to-day work, manage planned changes and oversee relevant externally provided processes.
Read the full guide →Clause 8.2 · Operation
Information security risk assessment
Perform risk assessments using the established method at planned intervals and when significant changes could alter the risk picture.
Read the full guide →Clause 8.3 · Operation
Information security risk treatment
Implement the approved treatment plan, track delivery and maintain evidence that selected responses and controls are operating.
Read the full guide →Clause 9.1 · Performance evaluation
Monitoring, measurement, analysis and evaluation
Decide what information is needed to judge ISMS performance and control effectiveness, then collect, analyse and evaluate it consistently.
Read the full guide →Clause 9.2 · Performance evaluation
Internal audit
Use independent, evidence-based review to determine whether the ISMS conforms to planned arrangements and is effectively maintained.
Read the full guide →Clause 9.2.1 · Performance evaluation
General
Conduct internal audits at planned intervals to provide credible evidence about whether the ISMS is implemented, maintained and working as intended.
Read the full guide →Clause 9.2.2 · Performance evaluation
Internal audit programme
Plan and manage a risk-informed programme that defines audit frequency, methods, responsibilities, scope, criteria, reporting and follow-up.
Read the full guide →Clause 9.3 · Performance evaluation
Management review
Enable top management to evaluate whether the ISMS remains suitable, adequate and effective and to make informed decisions about its direction.
Read the full guide →Clause 9.3.1 · Performance evaluation
General
Run management reviews as a recurring governance process that evaluates the ISMS and directs necessary action.
Read the full guide →Clause 9.3.2 · Performance evaluation
Management review inputs
Bring together the information management needs to evaluate change, obligations, performance, risk, audit results and improvement opportunities.
Read the full guide →Clause 9.3.3 · Performance evaluation
Management review results
Capture management decisions about improvement, ISMS changes, resources and other actions arising from the review.
Read the full guide →Clause 10.1 · Improvement
Continual improvement
Use evidence and learning to make the ISMS progressively more suitable, adequate and effective rather than merely maintaining its current state.
Read the full guide →Clause 10.2 · Improvement
Nonconformity and corrective action
Respond to a failure by controlling its immediate effect, understanding why it happened, removing relevant causes and checking that the response worked.
Read the full guide →