Intro — INTERNATIONAL STANDARD
In simple words: ISO/IEC 27001 Third edition 2022-10 Information security, cybersecurity and privacy protection — Information security management systems — Requirements Sécurité de l'information, cybersécurité et protection de la vie privée — Systèmes de management de la sécurité de l'information — Exigences Reference number ISO/IEC… It is descriptive — it defines context or terms rather than imposing direct obligations.
Original text
ISO/IEC 27001
Third edition
2022-10
Information security, cybersecurity and privacy protection — Information security management systems — Requirements
Sécurité de l'information, cybersécurité et protection de la vie
privée — Systèmes de management de la sécurité de l'information — Exigences
Referen
Foreword
In simple words: ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical committees established… It contains 1 binding requirement ("shall/must" rules) organisations have to follow.
Original text
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical Commission) form the specialized system for worldwide standardization. National bodies that are members of ISO or IEC participate in the development of International Standards through technical commi
Introduction
In simple words: General This document has been prepared to provide requirements for establishing, implementing, maintaining and continually improving an information security management system. The adoption of an information security management system is a strategic decision for an organization. It is descriptive — it defines context or terms rather than imposing direct obligations.
Original text
General
This document has been prepared to provide requirements for establishing, implementing, maintaining and continually improving an information security management system. The adoption of an information security management system is a strategic decision for an organization. The establishment an
Scope
In simple words: This document specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. This document also includes requirements for the assessment and treatment of information security risks tailored to the needs… It is descriptive — it defines context or terms rather than imposing direct obligations.
Original text
This document specifies the requirements for establishing, implementing, maintaining and continually improving an information security management system within the context of the organization. This document also includes requirements for the assessment and treatment of information security risks tai
Normative references
In simple words: The following documents are referred to in the text in such a way that some or all of their content constitutes requirements of this document. For dated references, only the edition cited applies. It is descriptive — it defines context or terms rather than imposing direct obligations.
Original text
The following documents are referred to in the text in such a way that some or all of their content constitutes requirements of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applie
Terms and definitions
In simple words: For the purposes of this document, the terms and definitions given in ISO/IEC 27000 apply. ISO and IEC maintain terminology databases for use in standardization at the following addresses: ISO Online browsing platform: available at https://www.iso.org/obp IEC Electropedia: available at https://www.electropedia.org/ It is descriptive — it defines context or terms rather than imposing direct obligations.
Original text
For the purposes of this document, the terms and definitions given in ISO/IEC 27000 apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
ISO Online browsing platform: available at https://www.iso.org/obp
IEC Electropedia: available at https://www.e
Context of the organization
In simple words: It is descriptive — it defines context or terms rather than imposing direct obligations.
Understanding the organization and its context
In simple words: The organization shall determine external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcome(s) of its information security management system. NOTE Determining these issues refers to establishing the external and internal context of the organization… It contains 1 binding requirement ("shall/must" rules) organisations have to follow.
Original text
The organization shall determine external and internal issues that are relevant to its purpose and that affect its ability to achieve the intended outcome(s) of its information security management system.
NOTE Determining these issues refers to establishing the external and internal context of the o
Understanding the needs and expectations of interested parties
In simple words: The organization shall determine: interested parties that are relevant to the information security management system; the relevant requirements of these interested parties; It contains 1 binding requirement ("shall/must" rules) organisations have to follow.
Original text
The organization shall determine:
interested parties that are relevant to the information security management system;
the relevant requirements of these interested parties;
which of these requirements will be addressed through the information security management system.
NOTE The requirements of inte
Determining the scope of the information security management system
In simple words: The organization shall determine the boundaries and applicability of the information security management system to establish its scope. When determining this scope, the organization shall consider: the external and internal issues referred to in 4.1; It contains 3 binding requirements ("shall/must" rules) organisations have to follow.
Original text
The organization shall determine the boundaries and applicability of the information security management system to establish its scope.
When determining this scope, the organization shall consider:
the external and internal issues referred to in 4.1;
the requirements referred to in 4.2;
interfaces a