Implement ISO 27001 Information Security Management System. Configure ISMS controls and risk management. Use when implementing enterprise security frameworks.
Implement ISO 27001 Information Security Management System. Configure ISMS controls and risk management. Use when implementing enterprise security frameworks.
license
MIT
metadata
{"author":"devops-skills","version":"1.0"}
ISO 27001 Compliance
Implement an Information Security Management System (ISMS) aligned with ISO/IEC 27001:2022.
When to Use
Establishing an ISMS for the first time in an organization
Preparing for ISO 27001 certification audit
Conducting risk assessments and developing risk treatment plans
Creating the Statement of Applicability (SoA)
Transitioning from ISO 27001:2013 to the 2022 revision
Meeting customer or regulatory requirements for ISO 27001 certification
isms_scope:template:organization:"Company Name, Ltd."scope_statement:|
The ISMS covers the design, development, operation, and support of
the Company's cloud-based SaaS platform, including all supporting
infrastructure, personnel, and processes at the following locations.
included:locations:-"Primary office: 123 Main Street, City, Country"-"AWS us-east-1 and eu-west-1 regions"-"Remote workers accessing corporate systems"business_processes:-"Software development and deployment"-"Cloud infrastructure management"-"Customer data processing and storage"-"Customer support operations"-"Corporate IT and internal systems"information_assets:-"Customer data (PII, business data)"-"Source code and intellectual property"-"Employee personal data"-"Financial records"-"Security configurations and credentials"technology:-"AWS cloud infrastructure"-"SaaS application stack"-"Corporate IT systems (Google Workspace, Okta, Jira)"
Risk Assessment Process
risk_assessment:methodology:approach:"Asset-based risk assessment"risk_formula:"Risk = Likelihood x Impact"scale:"1-5 for both likelihood and impact (total 1-25)"likelihood_scale:1:"Rare - less than once per 5 years"2:"Unlikely - once per 2-5 years"3:"Possible - once per 1-2 years"4:"Likely - multiple times per year"5:"Almost Certain - monthly or more frequent"impact_scale:1:"Negligible - minimal operational impact, no data loss"2:"Minor - limited impact, small data exposure, <$10K cost"3:"Moderate - significant impact, data breach <1K records, <$100K cost"4:"Major - severe impact, large data breach, <$1M cost, regulatory action"5:"Critical - catastrophic, massive breach, >$1M cost, business viability at risk"risk_matrix:# Impact: 1 2 3 4 5likelihood_5: [5, 10, 15, 20, 25]
likelihood_4: [4, 8, 12, 16, 20]
likelihood_3: [3, 6, , , ]
[, , , , ]
[, , , , ]
[, ]
[, ]
[, ]
Statement of Applicability (SoA)
# ISO 27001:2022 Annex A Controls - Statement of Applicabilitysoa_template:organizational_controls_5:"A.5.1":control:"Policies for information security"applicable:truejustification:"Required to establish security governance"implementation:"Information security policy approved by CEO, reviewed annually""A.5.2":control:"Information security roles and responsibilities"applicable:truejustification:"Required for accountability"implementation:"RACI matrix for security responsibilities, CISO appointed""A.5.7":control:"Threat intelligence"applicable:truejustification:"Required for proactive threat management"implementation:"Subscribe to threat feeds, CVE monitoring, vendor advisories""A.5.15":control:"Access control"applicable:truejustification:"Required for data protection"implementation:"RBAC via Okta, least-privilege IAM policies, quarterly access reviews""A.5.23":control:"Information security for use of cloud services"applicable:true
Internal Audit Program
internal_audit:schedule:frequency:"Annual full cycle, quarterly focused audits"cycle:"All ISMS clauses and applicable Annex A controls audited over 12 months"audit_plan_template:audit_id:"IA-2025-Q1"scope:"Clauses 4-10, Annex A controls A.5.1-A.5.15"auditor:"Internal auditor (independent of audited area)"audit_dates:"2025-03-10 to 2025-03-14"areas:-area:"Access Control (A.5.15)"auditee:"IT Security Team"evidence_requested:-"Access review records from last quarter"-"Joiner/mover/leaver process records"-"Privileged access management logs"-area:"Risk Management (Clause 6.1)"auditee:"Risk Management Team"evidence_requested:-"Current risk register"-"Risk assessment methodology document"-"Management risk review meeting minutes"finding_categories:major_nonconformity:"Requirement not met, significant risk to ISMS effectiveness"minor_nonconformity:"Requirement partially met, limited risk"
Management Review Meeting
management_review:frequency:"At least annually, recommended quarterly"attendees:required:-"CEO or Managing Director"-"CISO or Information Security Manager"-"Department heads"optional:-"Internal auditor"-"Risk manager"-"External consultant"mandatory_inputs:-"Status of actions from previous management reviews"-"Changes in external and internal issues relevant to the ISMS"-"Information security performance (metrics and KPIs)"-"Audit results (internal and external)"-"Incident trends and nonconformities"-"Risk assessment results and risk treatment plan status"-"Interested party feedback"-"Opportunities for continual improvement"mandatory_outputs:-"Decisions on continual improvement opportunities"-"Decisions on changes needed to the ISMS"-"Resource allocation decisions"-"Updated risk acceptance decisions"kpis_to_report:-"Number and severity of security incidents"