Chapter 1
ISMS Fundamentals + the ISO 27000 Family
What an ISMS is, why organisations pursue certification, how the ISO 27000 family fits together (27001 mandatory, 27002 guidance, 27005 risk, 27017 cloud, 27701 privacy), and the Plan-Do-Check-Act cycle.
Key concepts
- Confidentiality, Integrity, Availability (CIA triad)
- ISO 27001 (requirements) vs ISO 27002 (implementation guidance)
- Statement of Applicability (SoA) is the load-bearing document
- PDCA lifecycle
- Certification body vs accreditation body distinction
Hands-on practice
Day 5: Define ISMS scope + boundary for SwiftLend NBFC →