ISO 27001’s structure and PDCA
The ISO 27001 standard defines the criteria for creating, implementing, and maintaining an organization’s ISMS. The complete name of the standard is Information security, cybersecurity and privacy protection — Information security management systems — Requirements (as per the latest version released in 2022) and it consists of two parts:
- The main part: This consists of 11 clauses (0 to 10), in which clauses 0 to 3 describe the standard itself and clauses 4 to 10 describe the requirements your company must meet to be compliant with the standard
- Annex A: This consists of 93 controls that are to be considered while implementing ISMS
Annex L
For each management discipline, ISO has developed a management system standard. Although the technical content of each standard differs according to the relevant management discipline, ISO has developed a high-level framework structure (originally called Annex SL, and...