Context of the organisation
Understand the organisation and the needs of interested parties; determine ISMS scope.
The international standard for information-security management systems (ISMS), certifiable by accredited certification bodies.
ISO/IEC 27001 specifies the requirements for an Information Security Management System - a risk-based, top-down approach to protecting information assets through policies, processes and controls. The 2022 revision streamlines the Annex A control set to 93 controls organised across four themes (organisational, people, physical, technological). Certification is widely used as procurement evidence in Australia and is commonly accepted as an "equivalent" for the CIRMP cyber hazard requirement.
Any organisation pursuing a certifiable information-security management system. Widely adopted in financial services, SaaS, managed services and supply-chain-critical vendors.
Understand the organisation and the needs of interested parties; determine ISMS scope.
Top-management commitment, policy and assignment of roles and responsibilities.
Risk assessment and risk-treatment planning against information-security objectives.
Resources, awareness, communication, documented information and operational control.
Monitoring, internal audit and management review of the ISMS.
Nonconformity and corrective action; continual improvement.
Control set grouped into organisational, people, physical and technological themes.
Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.