SlideShare a Scribd company logo
1 of 11
ISO 27001
Agenda
§ What is ISO 27001
§ The PDCA Model
§ Steps to achieve ISO
27001Certification
PDCA Model
§ The "Plan-Do-Check-Act" (PDCA) model applies at different levels throughout the ISMS (cycles within cycles)
§ The diagram illustrates how an ISMS takes as input the information security requirements and expectations and through the PDCA cycle
produces managed information security outcomes that satisfy those requirements and expectations
Information security requirements
and expectations
Managed information security
PDCA Model
§ Plan (establish the ISMS)
Establish ISMS policy, objectives, processes and procedures relevant to managing risk and improving information security to deliver results in
accordance with an organization’s overall policies and objectives
§ Do (implement and operate the ISMS)
Implement and operate the ISMS policy, controls, processes and procedures
§ Check (monitor and review the ISMS)
Assess and, where applicable, measure process performance against ISMS policy, objectives and practical experience and report the results
to management for review
§ Act (maintain and improve the ISMS)
Take corrective and preventive actions, based on the results of the internal ISMS audit and management review or other relevant information,
to achieve continual improvement of the ISMS
10 Steps to Achieve ISO 27001
Step 1: Decision
§ Senior management need to be behind the decision for ISO 27001 certification. There is definite value in communicating this internally,
it enforces the company’s aspiration to pursue best practice
§ What is needed? Concise and positive briefing to senior management outlining benefits and how it provides a platform for business
growth
Step 2: ISO Management Representative
§ The company appoints a responsible and knowledgeable manager to run the program and implementation. This person will become the
company’s ISO 27001 specialist, understanding the controls and milestones needed towards accreditation
§ What is needed? Selection of the right individual with a specific job description and knowledge of ISO and ISMS requirements
10 Steps to Achieve ISO 27001
Step 3: Gap Analysis and Risk Assessment
§ An assessment of risk or a gap analysis is conducted to find out what can go wrong and which threats endanger the Confidentiality, Integrity
and Availability of information. This is to understand the maturity of existing controls within the business and to determine the risk profile
§ What is needed? The gap analysis followed by a risk assessment of all in scope people, processes and technology performed by a qualified
auditor. Understanding the maturity of controls and risk profile
Step 4: Scope & Implementation Plan
§ The review of output from the gap analysis allows the business to validate the scope of implementation and the functional / operational
boundaries. For each risk identified, appropriate controls are set to manage the risk in a systematic way. This will ensure nothing important is
missed. Important milestones, time requirements, dates for any pre assessment and staged audits are set
§ What is needed? A step by step concise guide to explain the ISO 27001 process in sufficient detail
10 Steps to Achieve ISO 27001
Step 5: Employee Introduction
§ It is important to engage with employees from the beginning to ensure they buy in to the ISO 27001 certification process and respond
appropriately. Also to help them to understand the individual, company and client benefits
§ What is needed? A short and easy-to-understand ISO 27001 and security introduction briefing that focuses on how employees are affected
and their role in the successful implementation
Step 6: Documentation, documentation, documentation!
§ ISO 27001 certification requires extensive documentation addressing all relevant millstones and individual controls. This forms the criteria the
company is measured against to meet the ISO standard
§ What is needed? A set of policies, standards and procedures to ensure the business is adhering to all requirements in an efficient and
achievable manner
10 Steps to Achieve ISO 27001
Step 7: Realisation
§ With the gap analysis, scope and documentation ready, it is time to put new processes into ‘business as usual’ throughout the company to start
realising the many benefits of ISO 27001. At this stage it would be beneficial to conduct a pre assessment to ensure the company is on the
right track and validate the evidence
§ What is needed? Pre assessments forms, checklists and the gathering of evidence. Communication to staff about the revised processes, the
need to adopt them fully and report back on what isn’t working
Step 8: Internal ISO 27001 Audits
§ ISO 27001 requires an internal audit to assess where the company is at with the milestones and the implementation phase. An auditor will
complete documentation assessing the risk, noting controls and remediation to highlight the improvements required
§ What is needed? An experienced internal or external auditor. Audit tools that include forms, complete audit checklists and audit reports
10 Steps to Achieve ISO 27001
Step 9: ISO 27001 Certification
§ The most important step is to pass the ISO 27001 certification audit. An independent assessor will issue a certificate stating that the
business is meeting the ISO 27001 controls and requirements. The appointed internal representative needs to be confident with the
process they have followed and consider how to best interact with the assessor
§ What is needed? Employee preparation for the ISO 27001 certification including questions that may be asked and the areas the audit
will focus on. An independent assessor from a reputable company
Step 10: Maintaining the ISO 27001 Certification
§ It is important to keep the ISO management system working by its integration into daily operations. The business should focus on
continual improvement
§ What is needed? A reinforcement message to employees. Focus on maintaining the standards through an internal champion. Treat it as
integral component of the business processes and not a one off project
Question & Answer
?
Damco iso   27001

More Related Content

What's hot

Efforts Toward Awareness.9 Oct2010
Efforts Toward Awareness.9 Oct2010Efforts Toward Awareness.9 Oct2010
Efforts Toward Awareness.9 Oct2010krsinghal
 
Internal Auditor Course
Internal Auditor CourseInternal Auditor Course
Internal Auditor CourseDan Stehling
 
Introduction of iso9001
Introduction of iso9001Introduction of iso9001
Introduction of iso9001Arvind sahu
 
NQA - ISO 9001 Implementation Guide
NQA - ISO 9001 Implementation GuideNQA - ISO 9001 Implementation Guide
NQA - ISO 9001 Implementation GuideNA Putra
 
FAQ - About ISO Certification
FAQ - About ISO CertificationFAQ - About ISO Certification
FAQ - About ISO CertificationIBEX SYSTEMS
 
ISO 13485 | ISO 13485 Training | ISO 13485 AWARENESS TRAINING
ISO 13485 | ISO 13485 Training | ISO 13485 AWARENESS TRAININGISO 13485 | ISO 13485 Training | ISO 13485 AWARENESS TRAINING
ISO 13485 | ISO 13485 Training | ISO 13485 AWARENESS TRAININGhimalya sharma
 
8 Hal Baru Sistem Manajemen Mutu ISO 9001:2015
8 Hal Baru Sistem Manajemen Mutu ISO 9001:20158 Hal Baru Sistem Manajemen Mutu ISO 9001:2015
8 Hal Baru Sistem Manajemen Mutu ISO 9001:2015Ekhsan Hari Nuryanto
 
Iso 9001 2015 iso geek
Iso 9001 2015 iso geekIso 9001 2015 iso geek
Iso 9001 2015 iso geekVarinder Kumar
 
NQA Ten Tips for Planning and Preparing
NQA Ten Tips for Planning and PreparingNQA Ten Tips for Planning and Preparing
NQA Ten Tips for Planning and PreparingNQA
 
Project Plan For The Implementation Of An Iso9001 2000
Project Plan For The Implementation Of An Iso9001 2000Project Plan For The Implementation Of An Iso9001 2000
Project Plan For The Implementation Of An Iso9001 2000ahmad bassiouny
 
ISO 9001:2015 Review and Why It Is Good (10/28/16)
ISO 9001:2015 Review and Why It Is Good (10/28/16)ISO 9001:2015 Review and Why It Is Good (10/28/16)
ISO 9001:2015 Review and Why It Is Good (10/28/16)Colin Gray
 
Implementing Iso 9001 2000
Implementing Iso 9001 2000Implementing Iso 9001 2000
Implementing Iso 9001 2000Dan Junkins
 
NQA 10 Steps to IMS Guide
NQA 10 Steps to IMS GuideNQA 10 Steps to IMS Guide
NQA 10 Steps to IMS GuideNQA
 
Added value of an integrated management system
Added value of an integrated management systemAdded value of an integrated management system
Added value of an integrated management systemPECB
 

What's hot (20)

Efforts Toward Awareness.9 Oct2010
Efforts Toward Awareness.9 Oct2010Efforts Toward Awareness.9 Oct2010
Efforts Toward Awareness.9 Oct2010
 
Internal Auditor Course
Internal Auditor CourseInternal Auditor Course
Internal Auditor Course
 
Introduction of iso9001
Introduction of iso9001Introduction of iso9001
Introduction of iso9001
 
NQA - ISO 9001 Implementation Guide
NQA - ISO 9001 Implementation GuideNQA - ISO 9001 Implementation Guide
NQA - ISO 9001 Implementation Guide
 
FAQ - About ISO Certification
FAQ - About ISO CertificationFAQ - About ISO Certification
FAQ - About ISO Certification
 
Iso 9001 implementation methodology
Iso 9001 implementation methodologyIso 9001 implementation methodology
Iso 9001 implementation methodology
 
ISO 13485 | ISO 13485 Training | ISO 13485 AWARENESS TRAINING
ISO 13485 | ISO 13485 Training | ISO 13485 AWARENESS TRAININGISO 13485 | ISO 13485 Training | ISO 13485 AWARENESS TRAINING
ISO 13485 | ISO 13485 Training | ISO 13485 AWARENESS TRAINING
 
8 Hal Baru Sistem Manajemen Mutu ISO 9001:2015
8 Hal Baru Sistem Manajemen Mutu ISO 9001:20158 Hal Baru Sistem Manajemen Mutu ISO 9001:2015
8 Hal Baru Sistem Manajemen Mutu ISO 9001:2015
 
ISO 9001 Made Easy?
ISO 9001 Made Easy?ISO 9001 Made Easy?
ISO 9001 Made Easy?
 
Iso 9001 2015 iso geek
Iso 9001 2015 iso geekIso 9001 2015 iso geek
Iso 9001 2015 iso geek
 
NQA Ten Tips for Planning and Preparing
NQA Ten Tips for Planning and PreparingNQA Ten Tips for Planning and Preparing
NQA Ten Tips for Planning and Preparing
 
Implementing Iso 9001 2000
Implementing Iso 9001 2000Implementing Iso 9001 2000
Implementing Iso 9001 2000
 
Introduction to ISO 9001:2015
Introduction to ISO 9001:2015Introduction to ISO 9001:2015
Introduction to ISO 9001:2015
 
Project Plan For The Implementation Of An Iso9001 2000
Project Plan For The Implementation Of An Iso9001 2000Project Plan For The Implementation Of An Iso9001 2000
Project Plan For The Implementation Of An Iso9001 2000
 
ISO 9001:2015 Review and Why It Is Good (10/28/16)
ISO 9001:2015 Review and Why It Is Good (10/28/16)ISO 9001:2015 Review and Why It Is Good (10/28/16)
ISO 9001:2015 Review and Why It Is Good (10/28/16)
 
Iso 9001 transitioning 2008 TO 2015
Iso 9001 transitioning 2008 TO 2015Iso 9001 transitioning 2008 TO 2015
Iso 9001 transitioning 2008 TO 2015
 
Implementing Iso 9001 2000
Implementing Iso 9001 2000Implementing Iso 9001 2000
Implementing Iso 9001 2000
 
ISO9001-2015 3-25-19
ISO9001-2015   3-25-19ISO9001-2015   3-25-19
ISO9001-2015 3-25-19
 
NQA 10 Steps to IMS Guide
NQA 10 Steps to IMS GuideNQA 10 Steps to IMS Guide
NQA 10 Steps to IMS Guide
 
Added value of an integrated management system
Added value of an integrated management systemAdded value of an integrated management system
Added value of an integrated management system
 

Viewers also liked

June 2011 - Reinventing innovation
June 2011 - Reinventing innovationJune 2011 - Reinventing innovation
June 2011 - Reinventing innovationFGV Brazil
 
Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...
Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...
Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...Haocheng Quan
 
August 2013 - Brazil’s rising trade imbalance
August 2013 - Brazil’s rising trade imbalanceAugust 2013 - Brazil’s rising trade imbalance
August 2013 - Brazil’s rising trade imbalanceFGV Brazil
 
Poster: Very Open Data Project
Poster: Very Open Data ProjectPoster: Very Open Data Project
Poster: Very Open Data ProjectEdward Blurock
 
August 2014 - Can Brazil find a route to competitiveness?
August 2014 - Can Brazil find a route to competitiveness?August 2014 - Can Brazil find a route to competitiveness?
August 2014 - Can Brazil find a route to competitiveness?FGV Brazil
 
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 6
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 6Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 6
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 6Onroerend Erfgoed
 
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 1
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 1Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 1
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 1Onroerend Erfgoed
 
ChemConnect: Characterizing CombusAon KineAc Data with ontologies and meta-­‐...
ChemConnect: Characterizing CombusAon KineAc Data with ontologies and meta-­‐...ChemConnect: Characterizing CombusAon KineAc Data with ontologies and meta-­‐...
ChemConnect: Characterizing CombusAon KineAc Data with ontologies and meta-­‐...Edward Blurock
 

Viewers also liked (12)

Beneficial Ownership in Taxation: Its Dynamics and Challenges
Beneficial Ownership in Taxation: Its Dynamics and ChallengesBeneficial Ownership in Taxation: Its Dynamics and Challenges
Beneficial Ownership in Taxation: Its Dynamics and Challenges
 
June 2011 - Reinventing innovation
June 2011 - Reinventing innovationJune 2011 - Reinventing innovation
June 2011 - Reinventing innovation
 
Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...
Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...
Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...
 
August 2013 - Brazil’s rising trade imbalance
August 2013 - Brazil’s rising trade imbalanceAugust 2013 - Brazil’s rising trade imbalance
August 2013 - Brazil’s rising trade imbalance
 
Dasar-dasar Dokumenter (2)
Dasar-dasar Dokumenter (2)Dasar-dasar Dokumenter (2)
Dasar-dasar Dokumenter (2)
 
Poster: Very Open Data Project
Poster: Very Open Data ProjectPoster: Very Open Data Project
Poster: Very Open Data Project
 
Games
GamesGames
Games
 
August 2014 - Can Brazil find a route to competitiveness?
August 2014 - Can Brazil find a route to competitiveness?August 2014 - Can Brazil find a route to competitiveness?
August 2014 - Can Brazil find a route to competitiveness?
 
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 6
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 6Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 6
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 6
 
E. ambiental
E. ambientalE. ambiental
E. ambiental
 
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 1
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 1Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 1
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 1
 
ChemConnect: Characterizing CombusAon KineAc Data with ontologies and meta-­‐...
ChemConnect: Characterizing CombusAon KineAc Data with ontologies and meta-­‐...ChemConnect: Characterizing CombusAon KineAc Data with ontologies and meta-­‐...
ChemConnect: Characterizing CombusAon KineAc Data with ontologies and meta-­‐...
 

Similar to Damco iso 27001

Get iso 27000 certification in 7 steps
Get iso 27000 certification in 7 stepsGet iso 27000 certification in 7 steps
Get iso 27000 certification in 7 stepsBen Pournader
 
ISO 27001 Compliance Checklist 9 Step Implementation Guide.pptx
ISO 27001 Compliance Checklist 9 Step Implementation Guide.pptxISO 27001 Compliance Checklist 9 Step Implementation Guide.pptx
ISO 27001 Compliance Checklist 9 Step Implementation Guide.pptxSIS Certifications Pvt Ltd
 
Planning for-and implementing ISO 27001
Planning for-and implementing ISO 27001Planning for-and implementing ISO 27001
Planning for-and implementing ISO 27001Yerlin Sturdivant
 
ISO 27001 Certification - VA.pdf
ISO 27001 Certification - VA.pdfISO 27001 Certification - VA.pdf
ISO 27001 Certification - VA.pdfsabeenasaahir
 
What are the steps for ISO 9001 Certification
What are the steps for ISO 9001 CertificationWhat are the steps for ISO 9001 Certification
What are the steps for ISO 9001 Certificationhimalya sharma
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001PECB
 
ISO Certification in Dubai (2).pdf
ISO Certification in Dubai (2).pdfISO Certification in Dubai (2).pdf
ISO Certification in Dubai (2).pdfZoyaAbdul1
 
ISO 27001 Training | ISO 27001 Internal Auditor Training | ISMS Internal Audi...
ISO 27001 Training | ISO 27001 Internal Auditor Training | ISMS Internal Audi...ISO 27001 Training | ISO 27001 Internal Auditor Training | ISMS Internal Audi...
ISO 27001 Training | ISO 27001 Internal Auditor Training | ISMS Internal Audi...himalya sharma
 
formation iso 27001.pptx
formation iso 27001.pptxformation iso 27001.pptx
formation iso 27001.pptxFayemunoz
 
What is ISO 45001 certification (OH&SMS) requirements for organizations?
What is ISO 45001 certification (OH&SMS) requirements for organizations?What is ISO 45001 certification (OH&SMS) requirements for organizations?
What is ISO 45001 certification (OH&SMS) requirements for organizations?isocert2
 
What are the steps for ISO 50001 Certification
What are the steps for ISO 50001 CertificationWhat are the steps for ISO 50001 Certification
What are the steps for ISO 50001 Certificationhimalya sharma
 
What are the steps for ISO 14001 Certification
What are the steps for ISO 14001 CertificationWhat are the steps for ISO 14001 Certification
What are the steps for ISO 14001 Certificationhimalya sharma
 
Steps to iso 27001 implementation
Steps to iso 27001 implementationSteps to iso 27001 implementation
Steps to iso 27001 implementationRalf Braga
 
english_bok_ismp_202306.pptx
english_bok_ismp_202306.pptxenglish_bok_ismp_202306.pptx
english_bok_ismp_202306.pptxssuser00d6eb
 
ISO 9000 & ISO 14000: pptx..............
ISO 9000 & ISO 14000: pptx..............ISO 9000 & ISO 14000: pptx..............
ISO 9000 & ISO 14000: pptx..............GayatriBahatkar1
 

Similar to Damco iso 27001 (20)

Damco iso 27001
Damco iso   27001Damco iso   27001
Damco iso 27001
 
Get iso 27000 certification in 7 steps
Get iso 27000 certification in 7 stepsGet iso 27000 certification in 7 steps
Get iso 27000 certification in 7 steps
 
ISO 27001 Compliance Checklist 9 Step Implementation Guide.pptx
ISO 27001 Compliance Checklist 9 Step Implementation Guide.pptxISO 27001 Compliance Checklist 9 Step Implementation Guide.pptx
ISO 27001 Compliance Checklist 9 Step Implementation Guide.pptx
 
Planning for-and implementing ISO 27001
Planning for-and implementing ISO 27001Planning for-and implementing ISO 27001
Planning for-and implementing ISO 27001
 
Intro to ISO
Intro to ISOIntro to ISO
Intro to ISO
 
ISO 27001 Certification - VA.pdf
ISO 27001 Certification - VA.pdfISO 27001 Certification - VA.pdf
ISO 27001 Certification - VA.pdf
 
Internal audit day 1
Internal audit day 1Internal audit day 1
Internal audit day 1
 
What are the steps for ISO 9001 Certification
What are the steps for ISO 9001 CertificationWhat are the steps for ISO 9001 Certification
What are the steps for ISO 9001 Certification
 
Qsys Profile
Qsys ProfileQsys Profile
Qsys Profile
 
Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001Best Practices in Auditing ISO/IEC 27001
Best Practices in Auditing ISO/IEC 27001
 
ISO Certification in Dubai (2).pdf
ISO Certification in Dubai (2).pdfISO Certification in Dubai (2).pdf
ISO Certification in Dubai (2).pdf
 
ISO 9001 Certification India
ISO 9001 Certification IndiaISO 9001 Certification India
ISO 9001 Certification India
 
ISO 27001 Training | ISO 27001 Internal Auditor Training | ISMS Internal Audi...
ISO 27001 Training | ISO 27001 Internal Auditor Training | ISMS Internal Audi...ISO 27001 Training | ISO 27001 Internal Auditor Training | ISMS Internal Audi...
ISO 27001 Training | ISO 27001 Internal Auditor Training | ISMS Internal Audi...
 
formation iso 27001.pptx
formation iso 27001.pptxformation iso 27001.pptx
formation iso 27001.pptx
 
What is ISO 45001 certification (OH&SMS) requirements for organizations?
What is ISO 45001 certification (OH&SMS) requirements for organizations?What is ISO 45001 certification (OH&SMS) requirements for organizations?
What is ISO 45001 certification (OH&SMS) requirements for organizations?
 
What are the steps for ISO 50001 Certification
What are the steps for ISO 50001 CertificationWhat are the steps for ISO 50001 Certification
What are the steps for ISO 50001 Certification
 
What are the steps for ISO 14001 Certification
What are the steps for ISO 14001 CertificationWhat are the steps for ISO 14001 Certification
What are the steps for ISO 14001 Certification
 
Steps to iso 27001 implementation
Steps to iso 27001 implementationSteps to iso 27001 implementation
Steps to iso 27001 implementation
 
english_bok_ismp_202306.pptx
english_bok_ismp_202306.pptxenglish_bok_ismp_202306.pptx
english_bok_ismp_202306.pptx
 
ISO 9000 & ISO 14000: pptx..............
ISO 9000 & ISO 14000: pptx..............ISO 9000 & ISO 14000: pptx..............
ISO 9000 & ISO 14000: pptx..............
 

More from Dipin Sharma

2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoftDipin Sharma
 
2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoftDipin Sharma
 
2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoftDipin Sharma
 
2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoftDipin Sharma
 
Curriculum outline
Curriculum outlineCurriculum outline
Curriculum outlineDipin Sharma
 

More from Dipin Sharma (6)

2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoft
 
2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoft
 
2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoft
 
2016 holiday list damcosoft
2016 holiday list damcosoft2016 holiday list damcosoft
2016 holiday list damcosoft
 
Curriculum outline
Curriculum outlineCurriculum outline
Curriculum outline
 
Cucumber outline
Cucumber outlineCucumber outline
Cucumber outline
 

Recently uploaded

Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
rishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfrishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfmuskan1121w
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024christinemoorman
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMRavindra Nath Shukla
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...lizamodels9
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...anilsa9823
 
Catalogue ONG NUOC PPR DE NHAT .pdf
Catalogue ONG NUOC PPR DE NHAT      .pdfCatalogue ONG NUOC PPR DE NHAT      .pdf
Catalogue ONG NUOC PPR DE NHAT .pdfOrient Homes
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
Non Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxNon Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxAbhayThakur200703
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfpollardmorgan
 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear RegressionRavindra Nath Shukla
 
Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝soniya singh
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.Aaiza Hassan
 
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts ServiceVip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Serviceankitnayak356677
 

Recently uploaded (20)

Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
rishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdfrishikeshgirls.in- Rishikesh call girl.pdf
rishikeshgirls.in- Rishikesh call girl.pdf
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024
 
Monte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSMMonte Carlo simulation : Simulation using MCSM
Monte Carlo simulation : Simulation using MCSM
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
Lucknow 💋 Escorts in Lucknow - 450+ Call Girl Cash Payment 8923113531 Neha Th...
 
Catalogue ONG NUOC PPR DE NHAT .pdf
Catalogue ONG NUOC PPR DE NHAT      .pdfCatalogue ONG NUOC PPR DE NHAT      .pdf
Catalogue ONG NUOC PPR DE NHAT .pdf
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
Non Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptxNon Text Magic Studio Magic Design for Presentations L&P.pptx
Non Text Magic Studio Magic Design for Presentations L&P.pptx
 
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
 
Regression analysis: Simple Linear Regression Multiple Linear Regression
Regression analysis:  Simple Linear Regression Multiple Linear RegressionRegression analysis:  Simple Linear Regression Multiple Linear Regression
Regression analysis: Simple Linear Regression Multiple Linear Regression
 
Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝
Call Girls in Mehrauli Delhi 💯Call Us 🔝8264348440🔝
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts ServiceVip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
 

Damco iso 27001

  • 2. Agenda § What is ISO 27001 § The PDCA Model § Steps to achieve ISO 27001Certification
  • 3. PDCA Model § The "Plan-Do-Check-Act" (PDCA) model applies at different levels throughout the ISMS (cycles within cycles) § The diagram illustrates how an ISMS takes as input the information security requirements and expectations and through the PDCA cycle produces managed information security outcomes that satisfy those requirements and expectations Information security requirements and expectations Managed information security
  • 4. PDCA Model § Plan (establish the ISMS) Establish ISMS policy, objectives, processes and procedures relevant to managing risk and improving information security to deliver results in accordance with an organization’s overall policies and objectives § Do (implement and operate the ISMS) Implement and operate the ISMS policy, controls, processes and procedures § Check (monitor and review the ISMS) Assess and, where applicable, measure process performance against ISMS policy, objectives and practical experience and report the results to management for review § Act (maintain and improve the ISMS) Take corrective and preventive actions, based on the results of the internal ISMS audit and management review or other relevant information, to achieve continual improvement of the ISMS
  • 5. 10 Steps to Achieve ISO 27001 Step 1: Decision § Senior management need to be behind the decision for ISO 27001 certification. There is definite value in communicating this internally, it enforces the company’s aspiration to pursue best practice § What is needed? Concise and positive briefing to senior management outlining benefits and how it provides a platform for business growth Step 2: ISO Management Representative § The company appoints a responsible and knowledgeable manager to run the program and implementation. This person will become the company’s ISO 27001 specialist, understanding the controls and milestones needed towards accreditation § What is needed? Selection of the right individual with a specific job description and knowledge of ISO and ISMS requirements
  • 6. 10 Steps to Achieve ISO 27001 Step 3: Gap Analysis and Risk Assessment § An assessment of risk or a gap analysis is conducted to find out what can go wrong and which threats endanger the Confidentiality, Integrity and Availability of information. This is to understand the maturity of existing controls within the business and to determine the risk profile § What is needed? The gap analysis followed by a risk assessment of all in scope people, processes and technology performed by a qualified auditor. Understanding the maturity of controls and risk profile Step 4: Scope & Implementation Plan § The review of output from the gap analysis allows the business to validate the scope of implementation and the functional / operational boundaries. For each risk identified, appropriate controls are set to manage the risk in a systematic way. This will ensure nothing important is missed. Important milestones, time requirements, dates for any pre assessment and staged audits are set § What is needed? A step by step concise guide to explain the ISO 27001 process in sufficient detail
  • 7. 10 Steps to Achieve ISO 27001 Step 5: Employee Introduction § It is important to engage with employees from the beginning to ensure they buy in to the ISO 27001 certification process and respond appropriately. Also to help them to understand the individual, company and client benefits § What is needed? A short and easy-to-understand ISO 27001 and security introduction briefing that focuses on how employees are affected and their role in the successful implementation Step 6: Documentation, documentation, documentation! § ISO 27001 certification requires extensive documentation addressing all relevant millstones and individual controls. This forms the criteria the company is measured against to meet the ISO standard § What is needed? A set of policies, standards and procedures to ensure the business is adhering to all requirements in an efficient and achievable manner
  • 8. 10 Steps to Achieve ISO 27001 Step 7: Realisation § With the gap analysis, scope and documentation ready, it is time to put new processes into ‘business as usual’ throughout the company to start realising the many benefits of ISO 27001. At this stage it would be beneficial to conduct a pre assessment to ensure the company is on the right track and validate the evidence § What is needed? Pre assessments forms, checklists and the gathering of evidence. Communication to staff about the revised processes, the need to adopt them fully and report back on what isn’t working Step 8: Internal ISO 27001 Audits § ISO 27001 requires an internal audit to assess where the company is at with the milestones and the implementation phase. An auditor will complete documentation assessing the risk, noting controls and remediation to highlight the improvements required § What is needed? An experienced internal or external auditor. Audit tools that include forms, complete audit checklists and audit reports
  • 9. 10 Steps to Achieve ISO 27001 Step 9: ISO 27001 Certification § The most important step is to pass the ISO 27001 certification audit. An independent assessor will issue a certificate stating that the business is meeting the ISO 27001 controls and requirements. The appointed internal representative needs to be confident with the process they have followed and consider how to best interact with the assessor § What is needed? Employee preparation for the ISO 27001 certification including questions that may be asked and the areas the audit will focus on. An independent assessor from a reputable company Step 10: Maintaining the ISO 27001 Certification § It is important to keep the ISO management system working by its integration into daily operations. The business should focus on continual improvement § What is needed? A reinforcement message to employees. Focus on maintaining the standards through an internal champion. Treat it as integral component of the business processes and not a one off project