ISO 27001 - ISMS
PS3
Conduct a risk assessment
PS2
Define ISMS Scope
PS4
Manage identified risks
ISO 27001 (process)
Process Steps: 1. Security Policy 2. Define ISMS Scope 3. Conduct a risk assessment 4. Manage identified risks 5. Select control objectives & controls for implementation 6. Statement of applicability
PS1
Security Policy
ISO 27001 (description)
Security standard that formally specifies an Information Security Management System (ISMS) that is intended to bring information security under explicit management control.
PS6
Statement of applicability
PS5
Select control objectives & controls for implementation
SoA (ISO 27001 - Statement of Applicability)
Defines the INFOSEC controls and organization's approach to meeting them or rationale(s) for omissions