Summary
ISO 27001 evolved from the BS 7799 standard and garnered global recognition. ISO/IEC 27001 itself is divided into two parts, the first one comprising 11 clauses and the second one (Annex A) 93 controls. The clauses are categorized into phases of Plan, Do, Check, and Act for implementation. The decision to implement an ISMS by an organization can be planned better with the SWOT analysis tool. After implementation, the responsibility of adhering to legal and regulatory compliance is a priority. The accreditation and certification processes are the hierarchical steps in achieving the certificate. This chapter will have helped you understand the importance of analyzing the present status and context of the organization to implement an ISMS.
In the following chapter, we’ll go into the specifics of each clause, including the Annex A controls.