Implementation as work products
Implementation path along clauses 4 to 10
7 chapters put decisions, responsibilities and evidence in a defensible order.
- 01
Scope
Context and scope
Define the service context to be protected and its boundaries in a defensible way.
Expected work products
- Context analysis
- Register of parties
- Scope statement
- Interface map
Based on: ISO, KaitoSec
- 02
Governance
Leadership and governance
Anchor mandate, policy, roles and escalation paths.
Expected work products
- Leadership decision
- Policy
- Role model
- Committee calendar
Based on: ISO, KaitoSec
- 03
Risk
Risk and planning
Assess, treat and accept risks consistently.
Expected work products
- Risk methodology
- Asset linkage
- Risk register
- Treatment plan
Based on: ISO, ISO, KaitoSec
- 04
Controls
Controls and SoA
Select relevant controls, justify them and connect them to evidence.
Expected work products
- SoA
- Control owners
- Evidence matrix
- Action backlog
Based on: ISO, ISO, KaitoSec
- 05
Operation
Operation and enablement
Bring security processes, competences and document control into daily work.
Expected work products
- Operational processes
- Competence matrix
- Awareness plan
- Document control
Based on: ISO, KaitoSec
- 06
Evaluation
Evaluating performance
Establish measurement, internal audit and management review as steering.
Expected work products
- Metrics system
- Audit programme
- Audit reports
- Management decisions
Based on: ISO, ISO, ISO
- 07
Improvement
Improve and certify
Close deviations with a focus on root causes and demonstrate certification readiness.
Expected work products
- Correction register
- Effectiveness checks
- Readiness review
- Certification plan
Based on: ISO, KaitoSec