10.1 | Continual improvement | 0 |
10.2 | Nonconformity and corrective action | 0 |
2-3 | Normative references and terms | 0 |
4.1 | Understanding the organization and its context | 0 |
4.2 | Understanding the needs and expectations of interested parties | 0 |
4.2.1 | General: interested parties and their requirements | 0 |
4.2.2 | Legal, regulatory and other requirements | 0 |
4.2.3 | Principles of security management | 0 |
4.3 | Determining the scope of the security management system | 0 |
4.4 | Security management system | 0 |
5.1 | Leadership and commitment | 0 |
5.2 | Security policy | 0 |
5.2.1 | Establishing the security policy | 0 |
5.2.2 | Security policy requirements | 0 |
5.3 | Roles, responsibilities and authorities | 0 |
6.1 | Actions to address risks and opportunities | 0 |
6.1.1 | General: risks and opportunities of the management system | 0 |
6.1.2 | Determining security-related risks and identifying opportunities | 0 |
6.1.3 | Addressing security-related risks and exploiting opportunities | 0 |
6.2 | Security objectives and planning to achieve them | 0 |
6.2.1 | Establishing security objectives | 0 |
6.2.2 | Determining security objectives | 0 |
6.3 | Planning of changes | 0 |
7.1 | Resources | 0 |
7.2 | Competence | 0 |
7.3 | Awareness | 0 |
7.4 | Communication | 0 |
7.5 | Documented information | 0 |
7.5.1 | General: the documented information of the system | 0 |
7.5.2 | Creating and updating documented information | 0 |
7.5.3 | Control of documented information | 0 |
8.1 | Operational planning and control | 0 |
8.2 | Identification of processes and activities | 0 |
8.3 | Risk assessment and treatment | 0 |
8.4 | Controls | 0 |
8.5 | Security strategies, procedures, processes and treatments | 0 |
8.5.1 | Identification and selection of strategies and treatments | 0 |
8.5.2 | Resource requirements | 0 |
8.5.3 | Implementation of treatments | 0 |
8.6 | Security plans | 0 |
8.6.1 | General: security plans and the response structure | 0 |
8.6.2 | Response structure | 0 |
8.6.3 | Warning and communication | 0 |
8.6.4 | Content of the security plans | 0 |
8.6.5 | Recovery | 0 |
9.1 | Monitoring, measurement, analysis and evaluation | 0 |
9.2 | Internal audit | 0 |
9.2.1 | General: internal audits | 0 |
9.2.2 | Internal audit programme | 0 |
9.3 | Management review | 0 |
9.3.1 | General: management review | 0 |
9.3.2 | Management review inputs | 0 |
9.3.3 | Management review results | 0 |