SlideShare a Scribd company logo
Project proposal for ISO
27001:2013 implementation
Subtitle or presenter
Content
• Reasons for implementation
• Purpose of the project
• Benefits of an ISMS
• Implementation details
• Milestones
• Resources
• Deliverables
12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 2
Reasons for implementation
(1/2)
Primary reasons:
• Improve interested parties’ trust by assuring
compliance with their requirements
• Improve marketing edge (image and credibility)
by attaining certification to ISO 27001
• Reduce expenses related to information security
incidents
• Improve internal organization by better defining
responsibilities and duties
12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 3
Reasons for implementation
(1/2)
12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 4
Compliance
Marketing
edge
Lowering the
expenses
Optimizing
business
processes
Reasons for implementation
(2/2)
Secondary reasons:
• Integrate information security to business process
for better alignment
• Improve decisions by basing them on data from
the information security management system
• Create a culture of continual improvement of the
information security
• Improve employee, and other interested parties’,
engagement in information security improvement
12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 5
The purpose of the project
What do we want to achieve?
• Gain ISO 27001 certification by [date] through:
– Defining the ISMS framework
– Identifying the current risk scenario
– Selecting and implementing proper security controls
– Providing proper awareness, training, and education to the
users
– Providing relevant information to management for the first
critical review of the ISMS for continual improvement
– Selecting the proper certification body to certify the
system
12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 6
Implementation details
• Project manager: [insert name]
• Project sponsor: [insert name]
• Project duration: [insert number of months]
12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 7
Milestones
12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 8
Milestone Due date
Initiation
Planning ISMS framework
Risk assessment
Implementation
Internal Audit
Management Review
Corrective Actions
Certification Audit
Continual Improvement Setup
Resources (1/2)
12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 9
Human
resources
Internal resources – [list internal
resources, e.g., group name]
External resources – [list external
resources, e.g., consulting company]
Technical
resources
Tool – [Tool name]
Equipment – [list equipment needed]
Resources (2/2)
12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 10
Financial
resources
Amount: [define amount of money
needed to finish the project]
Cost types: [split costs according to the
cost type and include all resources
listed here, e.g., human resources –
internal and external, technical, and
other resources]
Other
resources
Documentation templates
Deliverables
• ISMS General requirements documents
• ISMS related documents defined by the
organization (e.g., documents for security
controls
• Definition of risk assessment methodology and
organization’s risk profile
• Measurement, analysis, and improvement
processes
12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 11
Project proposal for ISO
27001 implementation
Presenter’s name
12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 12
Click icon to add picture

More Related Content

Similar to Project_Proposal_for_ISO27001_Implementation_27001Academy_EN.pptx

Practical experiences of portfolio management
Practical experiences of portfolio managementPractical experiences of portfolio management
Practical experiences of portfolio management
Association for Project Management
 
Project plan for ISO 9001 Implementation
Project plan for ISO 9001 ImplementationProject plan for ISO 9001 Implementation
Project plan for ISO 9001 Implementation
technakama
 
Project Controls Expo, Oct 2012 - Planning – How to Succeed Hints and Tips fr...
Project Controls Expo, Oct 2012 - Planning – How to Succeed Hints and Tips fr...Project Controls Expo, Oct 2012 - Planning – How to Succeed Hints and Tips fr...
Project Controls Expo, Oct 2012 - Planning – How to Succeed Hints and Tips fr...
Project Controls Expo
 
Cisa 2013 ch3
Cisa 2013 ch3Cisa 2013 ch3
Cisa 2013 ch3
Aladdin Dandis
 
Beetra BI Practice
Beetra BI PracticeBeetra BI Practice
Beetra BI Practice
sajidpathan
 
Training on ASAP Methodology_11.10.2020.ppt
Training on ASAP Methodology_11.10.2020.pptTraining on ASAP Methodology_11.10.2020.ppt
Training on ASAP Methodology_11.10.2020.ppt
AshwaniKumar207236
 
PMP Training - Project Time Management Part 2
PMP Training - Project Time Management Part 2PMP Training - Project Time Management Part 2
PMP Training - Project Time Management Part 2
Skillogic Solutions
 
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Cloud Standards Customer Council
 
Training on ASAP Methodology.ppt
Training on ASAP Methodology.pptTraining on ASAP Methodology.ppt
Training on ASAP Methodology.ppt
AshwaniKumar207236
 
Pre-assessment & Data Sheet presentation template - 2023.pptx
Pre-assessment & Data Sheet presentation template - 2023.pptxPre-assessment & Data Sheet presentation template - 2023.pptx
Pre-assessment & Data Sheet presentation template - 2023.pptx
ssuserc79a6f
 
Sabiron PLM Project Methodology.pdf
Sabiron PLM Project Methodology.pdfSabiron PLM Project Methodology.pdf
Sabiron PLM Project Methodology.pdf
Brion Carroll (II)
 
Suchasmita Padhi Resume
Suchasmita Padhi ResumeSuchasmita Padhi Resume
Suchasmita Padhi Resume
Suchasmita Padhi
 
EPA Project - Andy Smith
EPA Project - Andy SmithEPA Project - Andy Smith
EPA Project - Andy Smith
Andy Smith
 
GuideIT Customer Success Criteria Guide
GuideIT Customer Success Criteria GuideGuideIT Customer Success Criteria Guide
GuideIT Customer Success Criteria Guide
Vision Concepts Infrastructure Services Solution
 
250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf
250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf
250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf
Addisu15
 
QM & PM in TT
QM & PM in TTQM & PM in TT
QM & PM in TT
Sadananda Sahu
 
130625 How to boost your PMO with the right information?- Tue 25th of June i...
130625  How to boost your PMO with the right information?- Tue 25th of June i...130625  How to boost your PMO with the right information?- Tue 25th of June i...
130625 How to boost your PMO with the right information?- Tue 25th of June i...
Thibaut De Vylder
 
EPA Presentation - Andy Smith
EPA Presentation - Andy SmithEPA Presentation - Andy Smith
EPA Presentation - Andy Smith
Andy Smith
 
Social Solutions Apricot 360: Client Case Management Software
Social Solutions Apricot 360: Client Case Management SoftwareSocial Solutions Apricot 360: Client Case Management Software
Social Solutions Apricot 360: Client Case Management Software
Jeffrey Haguewood
 
Brighttalk - Role of ChM in SI process(1)
Brighttalk - Role of ChM in SI process(1)Brighttalk - Role of ChM in SI process(1)
Brighttalk - Role of ChM in SI process(1)
Anthony Oxley
 

Similar to Project_Proposal_for_ISO27001_Implementation_27001Academy_EN.pptx (20)

Practical experiences of portfolio management
Practical experiences of portfolio managementPractical experiences of portfolio management
Practical experiences of portfolio management
 
Project plan for ISO 9001 Implementation
Project plan for ISO 9001 ImplementationProject plan for ISO 9001 Implementation
Project plan for ISO 9001 Implementation
 
Project Controls Expo, Oct 2012 - Planning – How to Succeed Hints and Tips fr...
Project Controls Expo, Oct 2012 - Planning – How to Succeed Hints and Tips fr...Project Controls Expo, Oct 2012 - Planning – How to Succeed Hints and Tips fr...
Project Controls Expo, Oct 2012 - Planning – How to Succeed Hints and Tips fr...
 
Cisa 2013 ch3
Cisa 2013 ch3Cisa 2013 ch3
Cisa 2013 ch3
 
Beetra BI Practice
Beetra BI PracticeBeetra BI Practice
Beetra BI Practice
 
Training on ASAP Methodology_11.10.2020.ppt
Training on ASAP Methodology_11.10.2020.pptTraining on ASAP Methodology_11.10.2020.ppt
Training on ASAP Methodology_11.10.2020.ppt
 
PMP Training - Project Time Management Part 2
PMP Training - Project Time Management Part 2PMP Training - Project Time Management Part 2
PMP Training - Project Time Management Part 2
 
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0Security for Cloud Computing: 10 Steps to Ensure Success V3.0
Security for Cloud Computing: 10 Steps to Ensure Success V3.0
 
Training on ASAP Methodology.ppt
Training on ASAP Methodology.pptTraining on ASAP Methodology.ppt
Training on ASAP Methodology.ppt
 
Pre-assessment & Data Sheet presentation template - 2023.pptx
Pre-assessment & Data Sheet presentation template - 2023.pptxPre-assessment & Data Sheet presentation template - 2023.pptx
Pre-assessment & Data Sheet presentation template - 2023.pptx
 
Sabiron PLM Project Methodology.pdf
Sabiron PLM Project Methodology.pdfSabiron PLM Project Methodology.pdf
Sabiron PLM Project Methodology.pdf
 
Suchasmita Padhi Resume
Suchasmita Padhi ResumeSuchasmita Padhi Resume
Suchasmita Padhi Resume
 
EPA Project - Andy Smith
EPA Project - Andy SmithEPA Project - Andy Smith
EPA Project - Andy Smith
 
GuideIT Customer Success Criteria Guide
GuideIT Customer Success Criteria GuideGuideIT Customer Success Criteria Guide
GuideIT Customer Success Criteria Guide
 
250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf
250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf
250250902-141-ISACA-NACACS-Auditing-IT-Projects-Audit-Program.pdf
 
QM & PM in TT
QM & PM in TTQM & PM in TT
QM & PM in TT
 
130625 How to boost your PMO with the right information?- Tue 25th of June i...
130625  How to boost your PMO with the right information?- Tue 25th of June i...130625  How to boost your PMO with the right information?- Tue 25th of June i...
130625 How to boost your PMO with the right information?- Tue 25th of June i...
 
EPA Presentation - Andy Smith
EPA Presentation - Andy SmithEPA Presentation - Andy Smith
EPA Presentation - Andy Smith
 
Social Solutions Apricot 360: Client Case Management Software
Social Solutions Apricot 360: Client Case Management SoftwareSocial Solutions Apricot 360: Client Case Management Software
Social Solutions Apricot 360: Client Case Management Software
 
Brighttalk - Role of ChM in SI process(1)
Brighttalk - Role of ChM in SI process(1)Brighttalk - Role of ChM in SI process(1)
Brighttalk - Role of ChM in SI process(1)
 

Recently uploaded

Poznań ACE event - 19.06.2024 Team 24 Wrapup slidedeck
Poznań ACE event - 19.06.2024 Team 24 Wrapup slidedeckPoznań ACE event - 19.06.2024 Team 24 Wrapup slidedeck
Poznań ACE event - 19.06.2024 Team 24 Wrapup slidedeck
FilipTomaszewski5
 
"Frontline Battles with DDoS: Best practices and Lessons Learned", Igor Ivaniuk
"Frontline Battles with DDoS: Best practices and Lessons Learned",  Igor Ivaniuk"Frontline Battles with DDoS: Best practices and Lessons Learned",  Igor Ivaniuk
"Frontline Battles with DDoS: Best practices and Lessons Learned", Igor Ivaniuk
Fwdays
 
AppSec PNW: Android and iOS Application Security with MobSF
AppSec PNW: Android and iOS Application Security with MobSFAppSec PNW: Android and iOS Application Security with MobSF
AppSec PNW: Android and iOS Application Security with MobSF
Ajin Abraham
 
PRODUCT LISTING OPTIMIZATION PRESENTATION.pptx
PRODUCT LISTING OPTIMIZATION PRESENTATION.pptxPRODUCT LISTING OPTIMIZATION PRESENTATION.pptx
PRODUCT LISTING OPTIMIZATION PRESENTATION.pptx
christinelarrosa
 
AI in the Workplace Reskilling, Upskilling, and Future Work.pptx
AI in the Workplace Reskilling, Upskilling, and Future Work.pptxAI in the Workplace Reskilling, Upskilling, and Future Work.pptx
AI in the Workplace Reskilling, Upskilling, and Future Work.pptx
Sunil Jagani
 
inQuba Webinar Mastering Customer Journey Management with Dr Graham Hill
inQuba Webinar Mastering Customer Journey Management with Dr Graham HillinQuba Webinar Mastering Customer Journey Management with Dr Graham Hill
inQuba Webinar Mastering Customer Journey Management with Dr Graham Hill
LizaNolte
 
Dandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity serverDandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity server
Antonios Katsarakis
 
GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)
Javier Junquera
 
"Choosing proper type of scaling", Olena Syrota
"Choosing proper type of scaling", Olena Syrota"Choosing proper type of scaling", Olena Syrota
"Choosing proper type of scaling", Olena Syrota
Fwdays
 
Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |
AstuteBusiness
 
Leveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and StandardsLeveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and Standards
Neo4j
 
Mutation Testing for Task-Oriented Chatbots
Mutation Testing for Task-Oriented ChatbotsMutation Testing for Task-Oriented Chatbots
Mutation Testing for Task-Oriented Chatbots
Pablo Gómez Abajo
 
The Microsoft 365 Migration Tutorial For Beginner.pptx
The Microsoft 365 Migration Tutorial For Beginner.pptxThe Microsoft 365 Migration Tutorial For Beginner.pptx
The Microsoft 365 Migration Tutorial For Beginner.pptx
operationspcvita
 
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectorsConnector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
DianaGray10
 
Essentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation ParametersEssentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation Parameters
Safe Software
 
Northern Engraving | Modern Metal Trim, Nameplates and Appliance Panels
Northern Engraving | Modern Metal Trim, Nameplates and Appliance PanelsNorthern Engraving | Modern Metal Trim, Nameplates and Appliance Panels
Northern Engraving | Modern Metal Trim, Nameplates and Appliance Panels
Northern Engraving
 
"NATO Hackathon Winner: AI-Powered Drug Search", Taras Kloba
"NATO Hackathon Winner: AI-Powered Drug Search",  Taras Kloba"NATO Hackathon Winner: AI-Powered Drug Search",  Taras Kloba
"NATO Hackathon Winner: AI-Powered Drug Search", Taras Kloba
Fwdays
 
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
Jason Yip
 
MySQL InnoDB Storage Engine: Deep Dive - Mydbops
MySQL InnoDB Storage Engine: Deep Dive - MydbopsMySQL InnoDB Storage Engine: Deep Dive - Mydbops
MySQL InnoDB Storage Engine: Deep Dive - Mydbops
Mydbops
 
LF Energy Webinar: Carbon Data Specifications: Mechanisms to Improve Data Acc...
LF Energy Webinar: Carbon Data Specifications: Mechanisms to Improve Data Acc...LF Energy Webinar: Carbon Data Specifications: Mechanisms to Improve Data Acc...
LF Energy Webinar: Carbon Data Specifications: Mechanisms to Improve Data Acc...
DanBrown980551
 

Recently uploaded (20)

Poznań ACE event - 19.06.2024 Team 24 Wrapup slidedeck
Poznań ACE event - 19.06.2024 Team 24 Wrapup slidedeckPoznań ACE event - 19.06.2024 Team 24 Wrapup slidedeck
Poznań ACE event - 19.06.2024 Team 24 Wrapup slidedeck
 
"Frontline Battles with DDoS: Best practices and Lessons Learned", Igor Ivaniuk
"Frontline Battles with DDoS: Best practices and Lessons Learned",  Igor Ivaniuk"Frontline Battles with DDoS: Best practices and Lessons Learned",  Igor Ivaniuk
"Frontline Battles with DDoS: Best practices and Lessons Learned", Igor Ivaniuk
 
AppSec PNW: Android and iOS Application Security with MobSF
AppSec PNW: Android and iOS Application Security with MobSFAppSec PNW: Android and iOS Application Security with MobSF
AppSec PNW: Android and iOS Application Security with MobSF
 
PRODUCT LISTING OPTIMIZATION PRESENTATION.pptx
PRODUCT LISTING OPTIMIZATION PRESENTATION.pptxPRODUCT LISTING OPTIMIZATION PRESENTATION.pptx
PRODUCT LISTING OPTIMIZATION PRESENTATION.pptx
 
AI in the Workplace Reskilling, Upskilling, and Future Work.pptx
AI in the Workplace Reskilling, Upskilling, and Future Work.pptxAI in the Workplace Reskilling, Upskilling, and Future Work.pptx
AI in the Workplace Reskilling, Upskilling, and Future Work.pptx
 
inQuba Webinar Mastering Customer Journey Management with Dr Graham Hill
inQuba Webinar Mastering Customer Journey Management with Dr Graham HillinQuba Webinar Mastering Customer Journey Management with Dr Graham Hill
inQuba Webinar Mastering Customer Journey Management with Dr Graham Hill
 
Dandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity serverDandelion Hashtable: beyond billion requests per second on a commodity server
Dandelion Hashtable: beyond billion requests per second on a commodity server
 
GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)
 
"Choosing proper type of scaling", Olena Syrota
"Choosing proper type of scaling", Olena Syrota"Choosing proper type of scaling", Olena Syrota
"Choosing proper type of scaling", Olena Syrota
 
Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |
 
Leveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and StandardsLeveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and Standards
 
Mutation Testing for Task-Oriented Chatbots
Mutation Testing for Task-Oriented ChatbotsMutation Testing for Task-Oriented Chatbots
Mutation Testing for Task-Oriented Chatbots
 
The Microsoft 365 Migration Tutorial For Beginner.pptx
The Microsoft 365 Migration Tutorial For Beginner.pptxThe Microsoft 365 Migration Tutorial For Beginner.pptx
The Microsoft 365 Migration Tutorial For Beginner.pptx
 
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectorsConnector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
 
Essentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation ParametersEssentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation Parameters
 
Northern Engraving | Modern Metal Trim, Nameplates and Appliance Panels
Northern Engraving | Modern Metal Trim, Nameplates and Appliance PanelsNorthern Engraving | Modern Metal Trim, Nameplates and Appliance Panels
Northern Engraving | Modern Metal Trim, Nameplates and Appliance Panels
 
"NATO Hackathon Winner: AI-Powered Drug Search", Taras Kloba
"NATO Hackathon Winner: AI-Powered Drug Search",  Taras Kloba"NATO Hackathon Winner: AI-Powered Drug Search",  Taras Kloba
"NATO Hackathon Winner: AI-Powered Drug Search", Taras Kloba
 
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
 
MySQL InnoDB Storage Engine: Deep Dive - Mydbops
MySQL InnoDB Storage Engine: Deep Dive - MydbopsMySQL InnoDB Storage Engine: Deep Dive - Mydbops
MySQL InnoDB Storage Engine: Deep Dive - Mydbops
 
LF Energy Webinar: Carbon Data Specifications: Mechanisms to Improve Data Acc...
LF Energy Webinar: Carbon Data Specifications: Mechanisms to Improve Data Acc...LF Energy Webinar: Carbon Data Specifications: Mechanisms to Improve Data Acc...
LF Energy Webinar: Carbon Data Specifications: Mechanisms to Improve Data Acc...
 

Project_Proposal_for_ISO27001_Implementation_27001Academy_EN.pptx

  • 1. Project proposal for ISO 27001:2013 implementation Subtitle or presenter
  • 2. Content • Reasons for implementation • Purpose of the project • Benefits of an ISMS • Implementation details • Milestones • Resources • Deliverables 12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 2
  • 3. Reasons for implementation (1/2) Primary reasons: • Improve interested parties’ trust by assuring compliance with their requirements • Improve marketing edge (image and credibility) by attaining certification to ISO 27001 • Reduce expenses related to information security incidents • Improve internal organization by better defining responsibilities and duties 12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 3
  • 4. Reasons for implementation (1/2) 12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 4 Compliance Marketing edge Lowering the expenses Optimizing business processes
  • 5. Reasons for implementation (2/2) Secondary reasons: • Integrate information security to business process for better alignment • Improve decisions by basing them on data from the information security management system • Create a culture of continual improvement of the information security • Improve employee, and other interested parties’, engagement in information security improvement 12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 5
  • 6. The purpose of the project What do we want to achieve? • Gain ISO 27001 certification by [date] through: – Defining the ISMS framework – Identifying the current risk scenario – Selecting and implementing proper security controls – Providing proper awareness, training, and education to the users – Providing relevant information to management for the first critical review of the ISMS for continual improvement – Selecting the proper certification body to certify the system 12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 6
  • 7. Implementation details • Project manager: [insert name] • Project sponsor: [insert name] • Project duration: [insert number of months] 12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 7
  • 8. Milestones 12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 8 Milestone Due date Initiation Planning ISMS framework Risk assessment Implementation Internal Audit Management Review Corrective Actions Certification Audit Continual Improvement Setup
  • 9. Resources (1/2) 12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 9 Human resources Internal resources – [list internal resources, e.g., group name] External resources – [list external resources, e.g., consulting company] Technical resources Tool – [Tool name] Equipment – [list equipment needed]
  • 10. Resources (2/2) 12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 10 Financial resources Amount: [define amount of money needed to finish the project] Cost types: [split costs according to the cost type and include all resources listed here, e.g., human resources – internal and external, technical, and other resources] Other resources Documentation templates
  • 11. Deliverables • ISMS General requirements documents • ISMS related documents defined by the organization (e.g., documents for security controls • Definition of risk assessment methodology and organization’s risk profile • Measurement, analysis, and improvement processes 12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 11
  • 12. Project proposal for ISO 27001 implementation Presenter’s name 12/15/2023 Copyright ©2015 27001Academy. All rights reserved. 12 Click icon to add picture

Editor's Notes

  1. In this presentation we’ll show some relevant information about ISO 27001 implementation to help your management make an informed decision on how to better protect their organization’s information and business.
  2. The structure of your business case to support ISO27001 implementation.
  3. Interested parties: shareholders, employees, suppliers, regulators, management, clients, etc. For more detailed information about how to present this reasons, see the article http://www.iso27001standard.com/blog/2010/07/21/four-key-benefits-of-iso-27001-implementation/
  4. <Alternative version of the previous slide. Include only what fits you best> Interested parties: shareholders, employees, suppliers, regulators, management, clients, etc. For more detailed information about how to present this reasons, see the article http://www.iso27001standard.com/blog/2010/07/21/four-key-benefits-of-iso-27001-implementation/
  5. Project manager – write here the person who will coordinate the implementation of ISO 27001 Project sponsor – write here someone from the top management who will provide you with support for your project Project duration – calculate the time needed using this free calculator: http://www.iso27001standard.com/en/free-tools/free-calculator-duration-of-iso-27001-iso-22301-implementation