SlideShare a Scribd company logo
ISO 27001
Agenda
§ What is ISO 27001
§ The PDCA Model
§ Steps to achieve ISO
27001Certification
PDCA Model
§ The "Plan-Do-Check-Act" (PDCA) model applies at different levels throughout the ISMS (cycles within cycles)
§ The diagram illustrates how an ISMS takes as input the information security requirements and expectations and through the PDCA cycle
produces managed information security outcomes that satisfy those requirements and expectations
Information security requirements
and expectations
Managed information security
PDCA Model
§ Plan (establish the ISMS)
Establish ISMS policy, objectives, processes and procedures relevant to managing risk and improving information security to deliver results in
accordance with an organization’s overall policies and objectives
§ Do (implement and operate the ISMS)
Implement and operate the ISMS policy, controls, processes and procedures
§ Check (monitor and review the ISMS)
Assess and, where applicable, measure process performance against ISMS policy, objectives and practical experience and report the results
to management for review
§ Act (maintain and improve the ISMS)
Take corrective and preventive actions, based on the results of the internal ISMS audit and management review or other relevant information,
to achieve continual improvement of the ISMS
10 Steps to Achieve ISO 27001
Step 1: Decision
§ Senior management need to be behind the decision for ISO 27001 certification. There is definite value in communicating this internally,
it enforces the company’s aspiration to pursue best practice
§ What is needed? Concise and positive briefing to senior management outlining benefits and how it provides a platform for business
growth
Step 2: ISO Management Representative
§ The company appoints a responsible and knowledgeable manager to run the program and implementation. This person will become the
company’s ISO 27001 specialist, understanding the controls and milestones needed towards accreditation
§ What is needed? Selection of the right individual with a specific job description and knowledge of ISO and ISMS requirements
10 Steps to Achieve ISO 27001
Step 3: Gap Analysis and Risk Assessment
§ An assessment of risk or a gap analysis is conducted to find out what can go wrong and which threats endanger the Confidentiality, Integrity
and Availability of information. This is to understand the maturity of existing controls within the business and to determine the risk profile
§ What is needed? The gap analysis followed by a risk assessment of all in scope people, processes and technology performed by a qualified
auditor. Understanding the maturity of controls and risk profile
Step 4: Scope & Implementation Plan
§ The review of output from the gap analysis allows the business to validate the scope of implementation and the functional / operational
boundaries. For each risk identified, appropriate controls are set to manage the risk in a systematic way. This will ensure nothing important is
missed. Important milestones, time requirements, dates for any pre assessment and staged audits are set
§ What is needed? A step by step concise guide to explain the ISO 27001 process in sufficient detail
10 Steps to Achieve ISO 27001
Step 5: Employee Introduction
§ It is important to engage with employees from the beginning to ensure they buy in to the ISO 27001 certification process and respond
appropriately. Also to help them to understand the individual, company and client benefits
§ What is needed? A short and easy-to-understand ISO 27001 and security introduction briefing that focuses on how employees are affected
and their role in the successful implementation
Step 6: Documentation, documentation, documentation!
§ ISO 27001 certification requires extensive documentation addressing all relevant millstones and individual controls. This forms the criteria the
company is measured against to meet the ISO standard
§ What is needed? A set of policies, standards and procedures to ensure the business is adhering to all requirements in an efficient and
achievable manner
10 Steps to Achieve ISO 27001
Step 7: Realisation
§ With the gap analysis, scope and documentation ready, it is time to put new processes into ‘business as usual’ throughout the company to start
realising the many benefits of ISO 27001. At this stage it would be beneficial to conduct a pre assessment to ensure the company is on the
right track and validate the evidence
§ What is needed? Pre assessments forms, checklists and the gathering of evidence. Communication to staff about the revised processes, the
need to adopt them fully and report back on what isn’t working
Step 8: Internal ISO 27001 Audits
§ ISO 27001 requires an internal audit to assess where the company is at with the milestones and the implementation phase. An auditor will
complete documentation assessing the risk, noting controls and remediation to highlight the improvements required
§ What is needed? An experienced internal or external auditor. Audit tools that include forms, complete audit checklists and audit reports
10 Steps to Achieve ISO 27001
Step 9: ISO 27001 Certification
§ The most important step is to pass the ISO 27001 certification audit. An independent assessor will issue a certificate stating that the
business is meeting the ISO 27001 controls and requirements. The appointed internal representative needs to be confident with the
process they have followed and consider how to best interact with the assessor
§ What is needed? Employee preparation for the ISO 27001 certification including questions that may be asked and the areas the audit
will focus on. An independent assessor from a reputable company
Step 10: Maintaining the ISO 27001 Certification
§ It is important to keep the ISO management system working by its integration into daily operations. The business should focus on
continual improvement
§ What is needed? A reinforcement message to employees. Focus on maintaining the standards through an internal champion. Treat it as
integral component of the business processes and not a one off project
Question & Answer
?
Damco iso   27001

More Related Content

PPTX
Damco iso 27001
PDF
NQA ISO 9001 Implementation Guide
PDF
Ims integrated management system implementation steps-lakshy rev00-240914
PPTX
ISO 9001:2008 Internal Auditing of Quality Management Systems - Introduction
PPTX
100% Ims Presentation Issue 2.0 Dated Nov 09 [Autosaved]
PPTX
EGI Integrated Management System
PDF
How to successfully implement ISO 9001 in your company
Damco iso 27001
NQA ISO 9001 Implementation Guide
Ims integrated management system implementation steps-lakshy rev00-240914
ISO 9001:2008 Internal Auditing of Quality Management Systems - Introduction
100% Ims Presentation Issue 2.0 Dated Nov 09 [Autosaved]
EGI Integrated Management System
How to successfully implement ISO 9001 in your company

What's hot (20)

PDF
Efforts Toward Awareness.9 Oct2010
PPTX
Internal Auditor Course
PPT
Introduction of iso9001
PDF
NQA - ISO 9001 Implementation Guide
PPTX
FAQ - About ISO Certification
PDF
Iso 9001 implementation methodology
DOCX
ISO 13485 | ISO 13485 Training | ISO 13485 AWARENESS TRAINING
PDF
8 Hal Baru Sistem Manajemen Mutu ISO 9001:2015
PDF
ISO 9001 Made Easy?
PDF
Iso 9001 2015 iso geek
PDF
NQA Ten Tips for Planning and Preparing
PPT
Implementing Iso 9001 2000
PDF
PPT
Project Plan For The Implementation Of An Iso9001 2000
PPTX
ISO 9001:2015 Review and Why It Is Good (10/28/16)
PPTX
Iso 9001 transitioning 2008 TO 2015
PPT
Implementing Iso 9001 2000
PPTX
ISO9001-2015 3-25-19
PDF
NQA 10 Steps to IMS Guide
PPTX
Changes to ISO9001/ISO14001
Efforts Toward Awareness.9 Oct2010
Internal Auditor Course
Introduction of iso9001
NQA - ISO 9001 Implementation Guide
FAQ - About ISO Certification
Iso 9001 implementation methodology
ISO 13485 | ISO 13485 Training | ISO 13485 AWARENESS TRAINING
8 Hal Baru Sistem Manajemen Mutu ISO 9001:2015
ISO 9001 Made Easy?
Iso 9001 2015 iso geek
NQA Ten Tips for Planning and Preparing
Implementing Iso 9001 2000
Project Plan For The Implementation Of An Iso9001 2000
ISO 9001:2015 Review and Why It Is Good (10/28/16)
Iso 9001 transitioning 2008 TO 2015
Implementing Iso 9001 2000
ISO9001-2015 3-25-19
NQA 10 Steps to IMS Guide
Changes to ISO9001/ISO14001
Ad

Viewers also liked (12)

PDF
Beneficial Ownership in Taxation: Its Dynamics and Challenges
PDF
June 2011 - Reinventing innovation
PDF
Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...
PDF
August 2013 - Brazil’s rising trade imbalance
PPTX
Dasar-dasar Dokumenter (2)
PDF
Poster: Very Open Data Project
PDF
PDF
August 2014 - Can Brazil find a route to competitiveness?
PDF
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 6
PPTX
E. ambiental
PPTX
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 1
PPTX
ChemConnect: Characterizing CombusAon KineAc Data with ontologies and meta-­‐...
Beneficial Ownership in Taxation: Its Dynamics and Challenges
June 2011 - Reinventing innovation
Room-temperature synthesis of 3-dimentional Ag-graphene hybrid hydrogel with ...
August 2013 - Brazil’s rising trade imbalance
Dasar-dasar Dokumenter (2)
Poster: Very Open Data Project
August 2014 - Can Brazil find a route to competitiveness?
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 6
E. ambiental
Toelichting handboek ‘Verankeren van erfgoed in ruimtelijk beleid’ 1
ChemConnect: Characterizing CombusAon KineAc Data with ontologies and meta-­‐...
Ad

Similar to Damco iso 27001 (20)

PPTX
Damco iso 27001
PPTX
ISO 27001 Compliance Checklist 9 Step Implementation Guide.pptx
PPTX
Get iso 27000 certification in 7 steps
PDF
Implementing ISO 27001: A Step-by-Step Guide
PDF
A Comprehensive Guide To Information Security Excellence ISO 27001 Certificat...
PDF
ISO 27001 Information Security Management.pdf
PDF
Implementing ISO 27001: A Guide to Securing Your Organization
PPT
Prerequisites to ISO 27001 Certification
DOCX
A Comprehensive Guide to ISO 27001 Standard for Information Security
PPT
ISO 27001 Certification-The Gold Standard for Information Security
PPT
ISO 27001 Certification-The Gold Standard for Information Security-IAS-GULF-UAE
PPTX
Unlocking the Benefits of ISO 27001 Certification for Information Security.pptx
PPTX
"Safeguarding Your Organization's Data with ISO 27001"
PDF
Safeguarding Your organization ppt (1).pdf
PDF
Unlocking the Benefits of ISO 27001 Certification for Information Security.pdf
DOCX
Understanding ISO 27001: A Key Standard for Information Security Management
PPTX
6 steps how to get iso 27000 certification?
PDF
Why ISO 27001 Certification Matters for Your Business.pdf
PDF
NQA Your Complete Guide to ISO 27001
PDF
NQA Your Complete Guide to ISO 27001
Damco iso 27001
ISO 27001 Compliance Checklist 9 Step Implementation Guide.pptx
Get iso 27000 certification in 7 steps
Implementing ISO 27001: A Step-by-Step Guide
A Comprehensive Guide To Information Security Excellence ISO 27001 Certificat...
ISO 27001 Information Security Management.pdf
Implementing ISO 27001: A Guide to Securing Your Organization
Prerequisites to ISO 27001 Certification
A Comprehensive Guide to ISO 27001 Standard for Information Security
ISO 27001 Certification-The Gold Standard for Information Security
ISO 27001 Certification-The Gold Standard for Information Security-IAS-GULF-UAE
Unlocking the Benefits of ISO 27001 Certification for Information Security.pptx
"Safeguarding Your Organization's Data with ISO 27001"
Safeguarding Your organization ppt (1).pdf
Unlocking the Benefits of ISO 27001 Certification for Information Security.pdf
Understanding ISO 27001: A Key Standard for Information Security Management
6 steps how to get iso 27000 certification?
Why ISO 27001 Certification Matters for Your Business.pdf
NQA Your Complete Guide to ISO 27001
NQA Your Complete Guide to ISO 27001

More from Dipin Sharma (6)

PDF
2016 holiday list damcosoft
PDF
2016 holiday list damcosoft
PDF
2016 holiday list damcosoft
PDF
2016 holiday list damcosoft
PDF
Curriculum outline
PDF
Cucumber outline
2016 holiday list damcosoft
2016 holiday list damcosoft
2016 holiday list damcosoft
2016 holiday list damcosoft
Curriculum outline
Cucumber outline

Recently uploaded (20)

PDF
A Brief Introduction About Julia Allison
PDF
Unit 1 Cost Accounting - Cost sheet
PDF
Traveri Digital Marketing Seminar 2025 by Corey and Jessica Perlman
PPT
340036916-American-Literature-Literary-Period-Overview.ppt
PDF
Business model innovation report 2022.pdf
PDF
COST SHEET- Tender and Quotation unit 2.pdf
PDF
DOC-20250806-WA0002._20250806_112011_0000.pdf
PPTX
5 Stages of group development guide.pptx
PDF
kom-180-proposal-for-a-directive-amending-directive-2014-45-eu-and-directive-...
DOCX
unit 2 cost accounting- Tender and Quotation & Reconciliation Statement
PDF
Nidhal Samdaie CV - International Business Consultant
PPTX
Amazon (Business Studies) management studies
PPTX
The Marketing Journey - Tracey Phillips - Marketing Matters 7-2025.pptx
PDF
WRN_Investor_Presentation_August 2025.pdf
PPTX
ICG2025_ICG 6th steering committee 30-8-24.pptx
PDF
Katrina Stoneking: Shaking Up the Alcohol Beverage Industry
PDF
20250805_A. Stotz All Weather Strategy - Performance review July 2025.pdf
PDF
How to Get Funding for Your Trucking Business
PDF
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
PDF
Elevate Cleaning Efficiency Using Tallfly Hair Remover Roller Factory Expertise
A Brief Introduction About Julia Allison
Unit 1 Cost Accounting - Cost sheet
Traveri Digital Marketing Seminar 2025 by Corey and Jessica Perlman
340036916-American-Literature-Literary-Period-Overview.ppt
Business model innovation report 2022.pdf
COST SHEET- Tender and Quotation unit 2.pdf
DOC-20250806-WA0002._20250806_112011_0000.pdf
5 Stages of group development guide.pptx
kom-180-proposal-for-a-directive-amending-directive-2014-45-eu-and-directive-...
unit 2 cost accounting- Tender and Quotation & Reconciliation Statement
Nidhal Samdaie CV - International Business Consultant
Amazon (Business Studies) management studies
The Marketing Journey - Tracey Phillips - Marketing Matters 7-2025.pptx
WRN_Investor_Presentation_August 2025.pdf
ICG2025_ICG 6th steering committee 30-8-24.pptx
Katrina Stoneking: Shaking Up the Alcohol Beverage Industry
20250805_A. Stotz All Weather Strategy - Performance review July 2025.pdf
How to Get Funding for Your Trucking Business
SIMNET Inc – 2023’s Most Trusted IT Services & Solution Provider
Elevate Cleaning Efficiency Using Tallfly Hair Remover Roller Factory Expertise

Damco iso 27001

  • 2. Agenda § What is ISO 27001 § The PDCA Model § Steps to achieve ISO 27001Certification
  • 3. PDCA Model § The "Plan-Do-Check-Act" (PDCA) model applies at different levels throughout the ISMS (cycles within cycles) § The diagram illustrates how an ISMS takes as input the information security requirements and expectations and through the PDCA cycle produces managed information security outcomes that satisfy those requirements and expectations Information security requirements and expectations Managed information security
  • 4. PDCA Model § Plan (establish the ISMS) Establish ISMS policy, objectives, processes and procedures relevant to managing risk and improving information security to deliver results in accordance with an organization’s overall policies and objectives § Do (implement and operate the ISMS) Implement and operate the ISMS policy, controls, processes and procedures § Check (monitor and review the ISMS) Assess and, where applicable, measure process performance against ISMS policy, objectives and practical experience and report the results to management for review § Act (maintain and improve the ISMS) Take corrective and preventive actions, based on the results of the internal ISMS audit and management review or other relevant information, to achieve continual improvement of the ISMS
  • 5. 10 Steps to Achieve ISO 27001 Step 1: Decision § Senior management need to be behind the decision for ISO 27001 certification. There is definite value in communicating this internally, it enforces the company’s aspiration to pursue best practice § What is needed? Concise and positive briefing to senior management outlining benefits and how it provides a platform for business growth Step 2: ISO Management Representative § The company appoints a responsible and knowledgeable manager to run the program and implementation. This person will become the company’s ISO 27001 specialist, understanding the controls and milestones needed towards accreditation § What is needed? Selection of the right individual with a specific job description and knowledge of ISO and ISMS requirements
  • 6. 10 Steps to Achieve ISO 27001 Step 3: Gap Analysis and Risk Assessment § An assessment of risk or a gap analysis is conducted to find out what can go wrong and which threats endanger the Confidentiality, Integrity and Availability of information. This is to understand the maturity of existing controls within the business and to determine the risk profile § What is needed? The gap analysis followed by a risk assessment of all in scope people, processes and technology performed by a qualified auditor. Understanding the maturity of controls and risk profile Step 4: Scope & Implementation Plan § The review of output from the gap analysis allows the business to validate the scope of implementation and the functional / operational boundaries. For each risk identified, appropriate controls are set to manage the risk in a systematic way. This will ensure nothing important is missed. Important milestones, time requirements, dates for any pre assessment and staged audits are set § What is needed? A step by step concise guide to explain the ISO 27001 process in sufficient detail
  • 7. 10 Steps to Achieve ISO 27001 Step 5: Employee Introduction § It is important to engage with employees from the beginning to ensure they buy in to the ISO 27001 certification process and respond appropriately. Also to help them to understand the individual, company and client benefits § What is needed? A short and easy-to-understand ISO 27001 and security introduction briefing that focuses on how employees are affected and their role in the successful implementation Step 6: Documentation, documentation, documentation! § ISO 27001 certification requires extensive documentation addressing all relevant millstones and individual controls. This forms the criteria the company is measured against to meet the ISO standard § What is needed? A set of policies, standards and procedures to ensure the business is adhering to all requirements in an efficient and achievable manner
  • 8. 10 Steps to Achieve ISO 27001 Step 7: Realisation § With the gap analysis, scope and documentation ready, it is time to put new processes into ‘business as usual’ throughout the company to start realising the many benefits of ISO 27001. At this stage it would be beneficial to conduct a pre assessment to ensure the company is on the right track and validate the evidence § What is needed? Pre assessments forms, checklists and the gathering of evidence. Communication to staff about the revised processes, the need to adopt them fully and report back on what isn’t working Step 8: Internal ISO 27001 Audits § ISO 27001 requires an internal audit to assess where the company is at with the milestones and the implementation phase. An auditor will complete documentation assessing the risk, noting controls and remediation to highlight the improvements required § What is needed? An experienced internal or external auditor. Audit tools that include forms, complete audit checklists and audit reports
  • 9. 10 Steps to Achieve ISO 27001 Step 9: ISO 27001 Certification § The most important step is to pass the ISO 27001 certification audit. An independent assessor will issue a certificate stating that the business is meeting the ISO 27001 controls and requirements. The appointed internal representative needs to be confident with the process they have followed and consider how to best interact with the assessor § What is needed? Employee preparation for the ISO 27001 certification including questions that may be asked and the areas the audit will focus on. An independent assessor from a reputable company Step 10: Maintaining the ISO 27001 Certification § It is important to keep the ISO management system working by its integration into daily operations. The business should focus on continual improvement § What is needed? A reinforcement message to employees. Focus on maintaining the standards through an internal champion. Treat it as integral component of the business processes and not a one off project