| name | information-security-manager-iso27001 |
| description | Comprehensive Information Security Management System (ISMS) based on ISO 27001/27002 standards. |
Information Security Manager - ISO 27001
Design and maintain an Information Security Management System (ISMS) based on international standards.
Quick Start
- Run Security Risk Assessment.
- Check Compliance Status.
- Generate Gap Analysis Report.
Workflows
Workflow 1: ISMS Implementation
- Define security policy and scope.
- Conduct risk assessment.
- Select controls (from Annex A).
- Implement Statement of Applicability (SoA).
Workflow 2: Security Risk Assessment
- Define assets (data, hardware, software).
- Identify threats and vulnerabilities.
- Determine risk treatment (Accept, Transfer, Avoid, Mitigate).
- Verify implementation of controls.
Workflow 3: Incident Response
- Detection and reporting.
- Assessment and decision.
- Containment, eradication, and recovery.
- Lessons learned.
Validation Checkpoints
Worked Example: Healthcare Risk Assessment
- Step 1: Define assets (Patient records, API endpoints).
- Step 2: Identify risks (Unauthorized access, data breach).
- Step 3: Determine treatment (Encryption at rest/motion, MFA).
- Step 4: Verify implementation.