The ISMS concept is linked to ISO 27001 specification. It involves the following steps. First 3D;
|
|
Then RMICAAP stuff; |
|
|
|
And finally some disclosure type stuff |
|
|
In the statement of applicability justifications must be provided for not selecting particular controls. Certification of the above must take place annually. |