ISO27001 Flashcards
What is the standard that 27001 is built on?
Annex SL. This defines the standard structure for all ISO management systems. All management systems end in a ‘001’.
What is ISO27002
A set of guidelines around the implementation of controls. This is not mandatory, unlike the list in 27001 (Annex A), which are mandatory when they become part of the Statement of Applicability.
What guidelines should auditors follow?
ISO19011. This is not mandatory.
What are certifiers accredited against?
ISO17021 and the related auditor standard related to the MS. For 27000, this is ISO27006.
What are the 7 sections of 27001?
- Context of the organisation (organisation / scope).
- Leadership (commitment / policy / roles).
- Planning (risk planning / objectives).
- Support (resources / competence / awareness / comms).
- Operations (risk management).
- Performance evaluation (monitoring / audit).
- Improvement (corrective actions / improvement).
What are the 14 control areas in Annex A?
- Information security policy.
- Organisation of information security.
- Human resources.
- Asset management.
- Access control.
- Cryptography.
- Physical security.
- Operations security
- Communications security.
- System acquisition, development and maintenance.
- Supplier relationships.
- Information security incident management.
- Information security aspects of business continuity.
- Compliance.
What evidence should the auditor be looking for to verify the implementation of a requirement?
If the requirement is implemented, the auditor should seek evidence for it being Communicated, Executed, Understood and Effective.
Also, the auditor should seek evidence of it being Current, Coherent and Consistent.