Skip to content

Implementation as work products

Implementation path along clauses 4 to 10

7 chapters put decisions, responsibilities and evidence in a defensible order.

Back to ISO 27001

  1. 01

    Scope

    Context and scope

    Define the service context to be protected and its boundaries in a defensible way.

    Expected work products

    • Context analysis
    • Register of parties
    • Scope statement
    • Interface map

    Based on: ISO, KaitoSec

  2. 02

    Governance

    Leadership and governance

    Anchor mandate, policy, roles and escalation paths.

    Expected work products

    • Leadership decision
    • Policy
    • Role model
    • Committee calendar

    Based on: ISO, KaitoSec

  3. 03

    Risk

    Risk and planning

    Assess, treat and accept risks consistently.

    Expected work products

    • Risk methodology
    • Asset linkage
    • Risk register
    • Treatment plan

    Based on: ISO, ISO, KaitoSec

  4. 04

    Controls

    Controls and SoA

    Select relevant controls, justify them and connect them to evidence.

    Expected work products

    • SoA
    • Control owners
    • Evidence matrix
    • Action backlog

    Based on: ISO, ISO, KaitoSec

  5. 05

    Operation

    Operation and enablement

    Bring security processes, competences and document control into daily work.

    Expected work products

    • Operational processes
    • Competence matrix
    • Awareness plan
    • Document control

    Based on: ISO, KaitoSec

  6. 06

    Evaluation

    Evaluating performance

    Establish measurement, internal audit and management review as steering.

    Expected work products

    • Metrics system
    • Audit programme
    • Audit reports
    • Management decisions

    Based on: ISO, ISO, ISO

  7. 07

    Improvement

    Improve and certify

    Close deviations with a focus on root causes and demonstrate certification readiness.

    Expected work products

    • Correction register
    • Effectiveness checks
    • Readiness review
    • Certification plan

    Based on: ISO, KaitoSec