The document outlines the requirements for the ISO 27001:2013 standard concerning documentation, implementation, and auditing of Information Security Management Systems (ISMS). It details protocols for understanding organizational context, leadership responsibilities, risk management, resource allocation, performance evaluation, and continuous improvement within ISMS. It emphasizes the distinction between information security (IS) policies and ISMS policies, highlighting their respective management responsibilities.
Related topics: