27014-10.1 | Continual Improvement of Governance | 0 |
27014-4 | Concepts | 0 |
27014-5.1 | Governance Objectives | 0 |
27014-5.2 | Governance Principles | 0 |
27014-5.3 | Effectiveness | 0 |
27014-5.4 | Efficiency | 0 |
27014-5.5 | Alignment | 0 |
27014-5.6 | Continuous improvement | 47 |
27014-6.1 | Evaluate Process | 0 |
27014-6.2 | Direct Process | 0 |
27014-6.3 | Monitor Process | 0 |
27014-6.4 | Communicate Process | 0 |
27014-6.5 | Assure Process | 0 |
27014-7.1 | Roles and Responsibilities of Governing Body | 1 |
27014-7.2 | Roles of Executive Management | 0 |
27014-7.2.1 | Objective 1: Establish comprehensive information security | 0 |
27014-7.2.2 | Objective 2: Risk-based decision making | 0 |
27014-7.2.3 | Objective 3: Set direction of acquisition | 0 |
27014-7.2.4 | Objective 4: Ensure conformance | 0 |
27014-7.2.5 | Objective 5: Foster security-positive culture | 0 |
27014-7.2.6 | Objective 6: Performance relative to business outcomes | 0 |
27014-7.3 | Relationship Between Governing Body and Management | 0 |
27014-7.3.1 | Evaluate | 0 |
27014-7.3.2 | Direct | 0 |
27014-7.3.3 | Monitor | 0 |
27014-7.3.4 | Communicate | 0 |
27014-7.3.5 | Assure | 0 |
27014-8.1 | Alignment with Enterprise Governance | 0 |
27014-8.2 | Risk Appetite and Tolerance | 0 |
27014-8.3 | Resource Optimisation | 0 |
27014-8.4 | Performance Measurement | 0 |
27014-8.5 | Conformance and Compliance | 0 |
27014-9.1 | Stakeholder Engagement | 1 |
27014-9.2 | Reporting to External Parties | 0 |
1-5 | Scope, references, definitions, abbreviations, use and structure | 0 |
6 | Governance and management standards | 0 |
6.1 | Overview: governance and management of information security | 0 |
6.2 | Governance activities within the scope of an ISMS | 0 |
6.4 | Thread of governance within the organization | 0 |
7 | Entity governance and information security governance | 0 |
7.1 | Governance areas within an entity and the place of information security | 0 |
7.2 | Governance objectives | 0 |
7.2.1 | Objective 1: establish integrated, comprehensive, entity-wide information security | 0 |
7.2.2 | Objective 2: make decisions using a risk-based approach | 0 |
7.2.3 | Objective 3: set the direction of acquisition | 0 |
7.2.4 | Objective 4: ensure conformance with internal and external requirements | 0 |
7.2.5 | Objective 5: foster a security-positive culture | 0 |
7.2.6 | Objective 6: ensure security performance meets current and future requirements of the entity | 0 |
7.3 | Governance processes | 0 |
7.3.2 | Evaluate | 0 |
7.3.3 | Direct | 0 |
7.3.4 | Monitor | 0 |
7.3.5 | Communicate | 0 |
8 | The governing body's requirements on the ISMS | 0 |
8.1 | Organization and ISMS | 0 |
8.2 | Scenarios | 0 |
8.2.1 | Type A: the ISMS organization is the whole entity | 0 |
8.2.2 | Type B: the ISMS organization forms part of a larger entity | 0 |
8.2.3 | Type C: the ISMS organization includes parts of several entities | 0 |
ANNEXES | Annexes A to C (informative) | 0 |