SlideShare a Scribd company logo
1 of 11
ISO 27001
Agenda
§ What is ISO 27001
§ The PDCA Model
§ Steps to achieve ISO
27001Certification
PDCA Model
§ The "Plan-Do-Check-Act" (PDCA) model applies at different levels throughout the ISMS (cycles within cycles)
§ The diagram illustrates how an ISMS takes as input the information security requirements and expectations and through the PDCA cycle
produces managed information security outcomes that satisfy those requirements and expectations
Information security requirements
and expectations
Managed information security
PDCA Model
§ Plan (establish the ISMS)
Establish ISMS policy, objectives, processes and procedures relevant to managing risk and improving information security to deliver results in
accordance with an organization’s overall policies and objectives
§ Do (implement and operate the ISMS)
Implement and operate the ISMS policy, controls, processes and procedures
§ Check (monitor and review the ISMS)
Assess and, where applicable, measure process performance against ISMS policy, objectives and practical experience and report the results
to management for review
§ Act (maintain and improve the ISMS)
Take corrective and preventive actions, based on the results of the internal ISMS audit and management review or other relevant information,
to achieve continual improvement of the ISMS
10 Steps to Achieve ISO 27001
Step 1: Decision
§ Senior management need to be behind the decision for ISO 27001 certification. There is definite value in communicating this internally,
it enforces the company’s aspiration to pursue best practice
§ What is needed? Concise and positive briefing to senior management outlining benefits and how it provides a platform for business
growth
Step 2: ISO Management Representative
§ The company appoints a responsible and knowledgeable manager to run the program and implementation. This person will become the
company’s ISO 27001 specialist, understanding the controls and milestones needed towards accreditation
§ What is needed? Selection of the right individual with a specific job description and knowledge of ISO and ISMS requirements
10 Steps to Achieve ISO 27001
Step 3: Gap Analysis and Risk Assessment
§ An assessment of risk or a gap analysis is conducted to find out what can go wrong and which threats endanger the Confidentiality, Integrity
and Availability of information. This is to understand the maturity of existing controls within the business and to determine the risk profile
§ What is needed? The gap analysis followed by a risk assessment of all in scope people, processes and technology performed by a qualified
auditor. Understanding the maturity of controls and risk profile
Step 4: Scope & Implementation Plan
§ The review of output from the gap analysis allows the business to validate the scope of implementation and the functional / operational
boundaries. For each risk identified, appropriate controls are set to manage the risk in a systematic way. This will ensure nothing important is
missed. Important milestones, time requirements, dates for any pre assessment and staged audits are set
§ What is needed? A step by step concise guide to explain the ISO 27001 process in sufficient detail
10 Steps to Achieve ISO 27001
Step 5: Employee Introduction
§ It is important to engage with employees from the beginning to ensure they buy in to the ISO 27001 certification process and respond
appropriately. Also to help them to understand the individual, company and client benefits
§ What is needed? A short and easy-to-understand ISO 27001 and security introduction briefing that focuses on how employees are affected
and their role in the successful implementation
Step 6: Documentation, documentation, documentation!
§ ISO 27001 certification requires extensive documentation addressing all relevant millstones and individual controls. This forms the criteria the
company is measured against to meet the ISO standard
§ What is needed? A set of policies, standards and procedures to ensure the business is adhering to all requirements in an efficient and
achievable manner
10 Steps to Achieve ISO 27001
Step 7: Realisation
§ With the gap analysis, scope and documentation ready, it is time to put new processes into ‘business as usual’ throughout the company to start
realising the many benefits of ISO 27001. At this stage it would be beneficial to conduct a pre assessment to ensure the company is on the
right track and validate the evidence
§ What is needed? Pre assessments forms, checklists and the gathering of evidence. Communication to staff about the revised processes, the
need to adopt them fully and report back on what isn’t working
Step 8: Internal ISO 27001 Audits
§ ISO 27001 requires an internal audit to assess where the company is at with the milestones and the implementation phase. An auditor will
complete documentation assessing the risk, noting controls and remediation to highlight the improvements required
§ What is needed? An experienced internal or external auditor. Audit tools that include forms, complete audit checklists and audit reports
10 Steps to Achieve ISO 27001
Step 9: ISO 27001 Certification
§ The most important step is to pass the ISO 27001 certification audit. An independent assessor will issue a certificate stating that the
business is meeting the ISO 27001 controls and requirements. The appointed internal representative needs to be confident with the
process they have followed and consider how to best interact with the assessor
§ What is needed? Employee preparation for the ISO 27001 certification including questions that may be asked and the areas the audit
will focus on. An independent assessor from a reputable company
Step 10: Maintaining the ISO 27001 Certification
§ It is important to keep the ISO management system working by its integration into daily operations. The business should focus on
continual improvement
§ What is needed? A reinforcement message to employees. Focus on maintaining the standards through an internal champion. Treat it as
integral component of the business processes and not a one off project
Question & Answer
?
Damco iso   27001

More Related Content

What's hot

Efforts Toward Awareness.9 Oct2010
Efforts Toward Awareness.9 Oct2010Efforts Toward Awareness.9 Oct2010
Efforts Toward Awareness.9 Oct2010
krsinghal
 
Internal Auditor Course
Internal Auditor CourseInternal Auditor Course
Internal Auditor Course
Dan Stehling
 
Implementing Iso 9001 2000
Implementing Iso 9001 2000Implementing Iso 9001 2000
Implementing Iso 9001 2000
Dan Junkins
 

What's hot (20)

Efforts Toward Awareness.9 Oct2010
Efforts Toward Awareness.9 Oct2010Efforts Toward Awareness.9 Oct2010
Efforts Toward Awareness.9 Oct2010
 
Internal Auditor Course
Internal Auditor CourseInternal Auditor Course
Internal Auditor Course
 
Introduction of iso9001
Introduction of iso9001Introduction of iso9001
Introduction of iso9001
 
NQA - ISO 9001 Implementation Guide
NQA - ISO 9001 Implementation GuideNQA - ISO 9001 Implementation Guide
NQA - ISO 9001 Implementation Guide
 
FAQ - About ISO Certification
FAQ - About ISO CertificationFAQ - About ISO Certification
FAQ - About ISO Certification
 
Iso 9001 implementation methodology
Iso 9001 implementation methodologyIso 9001 implementation methodology
Iso 9001 implementation methodology
 
ISO 13485 | ISO 13485 Training | ISO 13485 AWARENESS TRAINING
ISO 13485 | ISO 13485 Training | ISO 13485 AWARENESS TRAININGISO 13485 | ISO 13485 Training | ISO 13485 AWARENESS TRAINING
ISO 13485 | ISO 13485 Training | ISO 13485 AWARENESS TRAINING
 
8 Hal Baru Sistem Manajemen Mutu ISO 9001:2015
8 Hal Baru Sistem Manajemen Mutu ISO 9001:20158 Hal Baru Sistem Manajemen Mutu ISO 9001:2015
8 Hal Baru Sistem Manajemen Mutu ISO 9001:2015
 
ISO 9001 Made Easy?
ISO 9001 Made Easy?ISO 9001 Made Easy?
ISO 9001 Made Easy?
 
Iso 9001 2015 iso geek
Iso 9001 2015 iso geekIso 9001 2015 iso geek
Iso 9001 2015 iso geek
 
NQA Ten Tips for Planning and Preparing
NQA Ten Tips for Planning and PreparingNQA Ten Tips for Planning and Preparing
NQA Ten Tips for Planning and Preparing
 
Implementing Iso 9001 2000
Implementing Iso 9001 2000Implementing Iso 9001 2000
Implementing Iso 9001 2000
 
Introduction to ISO 9001:2015
Introduction to ISO 9001:2015Introduction to ISO 9001:2015
Introduction to ISO 9001:2015
 
Project Plan For The Implementation Of An Iso9001 2000
Project Plan For The Implementation Of An Iso9001 2000Project Plan For The Implementation Of An Iso9001 2000
Project Plan For The Implementation Of An Iso9001 2000
 
ISO 9001:2015 Review and Why It Is Good (10/28/16)
ISO 9001:2015 Review and Why It Is Good (10/28/16)ISO 9001:2015 Review and Why It Is Good (10/28/16)
ISO 9001:2015 Review and Why It Is Good (10/28/16)
 
Iso 9001 transitioning 2008 TO 2015
Iso 9001 transitioning 2008 TO 2015Iso 9001 transitioning 2008 TO 2015
Iso 9001 transitioning 2008 TO 2015
 
Implementing Iso 9001 2000
Implementing Iso 9001 2000Implementing Iso 9001 2000
Implementing Iso 9001 2000
 
ISO9001-2015 3-25-19
ISO9001-2015   3-25-19ISO9001-2015   3-25-19
ISO9001-2015 3-25-19
 
NQA 10 Steps to IMS Guide
NQA 10 Steps to IMS GuideNQA 10 Steps to IMS Guide
NQA 10 Steps to IMS Guide
 
Added value of an integrated management system
Added value of an integrated management systemAdded value of an integrated management system
Added value of an integrated management system
 

Viewers also liked

Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...
Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...
Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...
Haocheng Quan
 
Poster: Very Open Data Project
Poster: Very Open Data ProjectPoster: Very Open Data Project
Poster: Very Open Data Project
Edward Blurock
 

Viewers also liked (12)

Beneficial Ownership in Taxation: Its Dynamics and Challenges
Beneficial Ownership in Taxation: Its Dynamics and ChallengesBeneficial Ownership in Taxation: Its Dynamics and Challenges
Beneficial Ownership in Taxation: Its Dynamics and Challenges
 
June 2011 - Reinventing innovation
June 2011 - Reinventing innovationJune 2011 - Reinventing innovation
June 2011 - Reinventing innovation
 
Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...
Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...
Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...
 
August 2013 - Brazil’s rising trade imbalance
August 2013 - Brazil’s rising trade imbalanceAugust 2013 - Brazil’s rising trade imbalance
August 2013 - Brazil’s rising trade imbalance
 
Dasar-dasar Dokumenter (2)
Dasar-dasar Dokumenter (2)Dasar-dasar Dokumenter (2)
Dasar-dasar Dokumenter (2)
 
Poster: Very Open Data Project
Poster: Very Open Data ProjectPoster: Very Open Data Project
Poster: Very Open Data Project
 
Games
GamesGames
Games
 
August 2014 - Can Brazil find a route to competitiveness?
August 2014 - Can Brazil find a route to competitiveness?August 2014 - Can Brazil find a route to competitiveness?
August 2014 - Can Brazil find a route to competitiveness?
 
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 6
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 6Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 6
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 6
 
E. ambiental
E. ambientalE. ambiental
E. ambiental
 
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 1
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 1Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 1
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 1
 
ChemConnect: Characterizing CombusAon KineAc Data with ontologies and meta-­‐...
ChemConnect: Characterizing CombusAon KineAc Data with ontologies and meta-­‐...ChemConnect: Characterizing CombusAon KineAc Data with ontologies and meta-­‐...
ChemConnect: Characterizing CombusAon KineAc Data with ontologies and meta-­‐...
 

Similar to Damco iso 27001

Similar to Damco iso 27001 (20)

Damco iso 27001
Damco iso   27001Damco iso   27001
Damco iso 27001
 
Get iso 27000 certification in 7 steps
Get iso 27000 certification in 7 stepsGet iso 27000 certification in 7 steps
Get iso 27000 certification in 7 steps
 
ISO 27001 Compliance Checklist 9 Step Implementation Guide.pptx
ISO 27001 Compliance Checklist 9 Step Implementation Guide.pptxISO 27001 Compliance Checklist 9 Step Implementation Guide.pptx
ISO 27001 Compliance Checklist 9 Step Implementation Guide.pptx
 
Planning for-and implementing ISO 27001
Planning for-and implementing ISO 27001Planning for-and implementing ISO 27001
Planning for-and implementing ISO 27001
 
Intro to ISO
Intro to ISOIntro to ISO
Intro to ISO
 
ISO 27001 Certification - VA.pdf
ISO 27001 Certification - VA.pdfISO 27001 Certification - VA.pdf
ISO 27001 Certification - VA.pdf
 
Internal audit day 1
Internal audit day 1Internal audit day 1
Internal audit day 1
 
What are the steps for ISO 9001 Certification
What are the steps for ISO 9001 CertificationWhat are the steps for ISO 9001 Certification
What are the steps for ISO 9001 Certification
 
Qsys Profile
Qsys ProfileQsys Profile
Qsys Profile
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001
 
ISO Certification in Dubai (2).pdf
ISO Certification in Dubai (2).pdfISO Certification in Dubai (2).pdf
ISO Certification in Dubai (2).pdf
 
ISO 9001 Certification India
ISO 9001 Certification IndiaISO 9001 Certification India
ISO 9001 Certification India
 
ISO 27001 Training | ISO 27001 Internal Auditor Training | ISMS Internal Audi...
ISO 27001 Training | ISO 27001 Internal Auditor Training | ISMS Internal Audi...ISO 27001 Training | ISO 27001 Internal Auditor Training | ISMS Internal Audi...
ISO 27001 Training | ISO 27001 Internal Auditor Training | ISMS Internal Audi...
 
formation iso 27001.pptx
formation iso 27001.pptxformation iso 27001.pptx
formation iso 27001.pptx
 
What is ISO 45001 certification (OH&SMS) requirements for organizations?
What is ISO 45001 certification (OH&SMS) requirements for organizations?What is ISO 45001 certification (OH&SMS) requirements for organizations?
What is ISO 45001 certification (OH&SMS) requirements for organizations?
 
What are the steps for ISO 50001 Certification
What are the steps for ISO 50001 CertificationWhat are the steps for ISO 50001 Certification
What are the steps for ISO 50001 Certification
 
What are the steps for ISO 14001 Certification
What are the steps for ISO 14001 CertificationWhat are the steps for ISO 14001 Certification
What are the steps for ISO 14001 Certification
 
Steps to iso 27001 implementation
Steps to iso 27001 implementationSteps to iso 27001 implementation
Steps to iso 27001 implementation
 
english_bok_ismp_202306.pptx
english_bok_ismp_202306.pptxenglish_bok_ismp_202306.pptx
english_bok_ismp_202306.pptx
 
ISO 9000 & ISO 14000: pptx..............
ISO 9000 & ISO 14000: pptx..............ISO 9000 & ISO 14000: pptx..............
ISO 9000 & ISO 14000: pptx..............
 

More from Dipin Sharma (6)

2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoft
 
2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoft
 
2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoft
 
2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoft
 
Curriculum outline
Curriculum outlineCurriculum outline
Curriculum outline
 
Cucumber outline
Cucumber outlineCucumber outline
Cucumber outline
 

Recently uploaded

Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
lizamodels9
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
dlhescort
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
amitlee9823
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
daisycvs
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
amitlee9823
 
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Anamikakaur10
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
Abortion pills in Kuwait Cytotec pills in Kuwait
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
dlhescort
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Sheetaleventcompany
 

Recently uploaded (20)

Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
Falcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in indiaFalcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in india
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investors
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service BangaloreCall Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
Call Girls Hebbal Just Call 👗 7737669865 👗 Top Class Call Girl Service Bangalore
 
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
 
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort ServiceMalegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
Malegaon Call Girls Service ☎ ️82500–77686 ☎️ Enjoy 24/7 Escort Service
 
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
Call Girls Zirakpur👧 Book Now📱7837612180 📞👉Call Girl Service In Zirakpur No A...
 
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
(Anamika) VIP Call Girls Napur Call Now 8617697112 Napur Escorts 24x7
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 

Damco iso 27001

  • 2. Agenda § What is ISO 27001 § The PDCA Model § Steps to achieve ISO 27001Certification
  • 3. PDCA Model § The "Plan-Do-Check-Act" (PDCA) model applies at different levels throughout the ISMS (cycles within cycles) § The diagram illustrates how an ISMS takes as input the information security requirements and expectations and through the PDCA cycle produces managed information security outcomes that satisfy those requirements and expectations Information security requirements and expectations Managed information security
  • 4. PDCA Model § Plan (establish the ISMS) Establish ISMS policy, objectives, processes and procedures relevant to managing risk and improving information security to deliver results in accordance with an organization’s overall policies and objectives § Do (implement and operate the ISMS) Implement and operate the ISMS policy, controls, processes and procedures § Check (monitor and review the ISMS) Assess and, where applicable, measure process performance against ISMS policy, objectives and practical experience and report the results to management for review § Act (maintain and improve the ISMS) Take corrective and preventive actions, based on the results of the internal ISMS audit and management review or other relevant information, to achieve continual improvement of the ISMS
  • 5. 10 Steps to Achieve ISO 27001 Step 1: Decision § Senior management need to be behind the decision for ISO 27001 certification. There is definite value in communicating this internally, it enforces the company’s aspiration to pursue best practice § What is needed? Concise and positive briefing to senior management outlining benefits and how it provides a platform for business growth Step 2: ISO Management Representative § The company appoints a responsible and knowledgeable manager to run the program and implementation. This person will become the company’s ISO 27001 specialist, understanding the controls and milestones needed towards accreditation § What is needed? Selection of the right individual with a specific job description and knowledge of ISO and ISMS requirements
  • 6. 10 Steps to Achieve ISO 27001 Step 3: Gap Analysis and Risk Assessment § An assessment of risk or a gap analysis is conducted to find out what can go wrong and which threats endanger the Confidentiality, Integrity and Availability of information. This is to understand the maturity of existing controls within the business and to determine the risk profile § What is needed? The gap analysis followed by a risk assessment of all in scope people, processes and technology performed by a qualified auditor. Understanding the maturity of controls and risk profile Step 4: Scope & Implementation Plan § The review of output from the gap analysis allows the business to validate the scope of implementation and the functional / operational boundaries. For each risk identified, appropriate controls are set to manage the risk in a systematic way. This will ensure nothing important is missed. Important milestones, time requirements, dates for any pre assessment and staged audits are set § What is needed? A step by step concise guide to explain the ISO 27001 process in sufficient detail
  • 7. 10 Steps to Achieve ISO 27001 Step 5: Employee Introduction § It is important to engage with employees from the beginning to ensure they buy in to the ISO 27001 certification process and respond appropriately. Also to help them to understand the individual, company and client benefits § What is needed? A short and easy-to-understand ISO 27001 and security introduction briefing that focuses on how employees are affected and their role in the successful implementation Step 6: Documentation, documentation, documentation! § ISO 27001 certification requires extensive documentation addressing all relevant millstones and individual controls. This forms the criteria the company is measured against to meet the ISO standard § What is needed? A set of policies, standards and procedures to ensure the business is adhering to all requirements in an efficient and achievable manner
  • 8. 10 Steps to Achieve ISO 27001 Step 7: Realisation § With the gap analysis, scope and documentation ready, it is time to put new processes into ‘business as usual’ throughout the company to start realising the many benefits of ISO 27001. At this stage it would be beneficial to conduct a pre assessment to ensure the company is on the right track and validate the evidence § What is needed? Pre assessments forms, checklists and the gathering of evidence. Communication to staff about the revised processes, the need to adopt them fully and report back on what isn’t working Step 8: Internal ISO 27001 Audits § ISO 27001 requires an internal audit to assess where the company is at with the milestones and the implementation phase. An auditor will complete documentation assessing the risk, noting controls and remediation to highlight the improvements required § What is needed? An experienced internal or external auditor. Audit tools that include forms, complete audit checklists and audit reports
  • 9. 10 Steps to Achieve ISO 27001 Step 9: ISO 27001 Certification § The most important step is to pass the ISO 27001 certification audit. An independent assessor will issue a certificate stating that the business is meeting the ISO 27001 controls and requirements. The appointed internal representative needs to be confident with the process they have followed and consider how to best interact with the assessor § What is needed? Employee preparation for the ISO 27001 certification including questions that may be asked and the areas the audit will focus on. An independent assessor from a reputable company Step 10: Maintaining the ISO 27001 Certification § It is important to keep the ISO management system working by its integration into daily operations. The business should focus on continual improvement § What is needed? A reinforcement message to employees. Focus on maintaining the standards through an internal champion. Treat it as integral component of the business processes and not a one off project