Phases of ISMS implementation
The following sections cover a step-by-step explanation of the various aspects, in sequential order, of ISMS implementation, based on the ISO 27001 standard.
1) Management support
Convincing management about an ISMS implementation can seem a daunting task. After all, management’s ultimate responsibility is the profitability of the company and decisions will be based on ROI (short for return on investment). Planning how to present the information in a way that management can understand and endorse is one of the key aspects of convincing them.
It is obvious that management will look for the benefits of the proposed ISMS. The following are the four most important benefits of an ISMS:
- Compliance: ISO 27001 can provide a methodology that enables a company to comply with multiple regulations concerning data protection, privacy, and IT governance (particularly if it is an organization in the financial sector, the healthcare industry, or...