1. Context and scope
Describe the organisation’s relevant internal and external context, interested parties, boundaries, and ISMS scope. Be clear about services, sites, assets, and exclusions.
Readiness guide
A plain-English overview of the management-system themes organisations commonly address when preparing for ISO/IEC 27001 assessment. It is not a substitute for the official standard, legal advice, or a complete implementation plan.
Core readiness themes
Every organisation is different. The appropriate scope, risks, controls, records, and evidence should reflect its services, information, technology, people, locations, contractual commitments, and regulatory environment.
Describe the organisation’s relevant internal and external context, interested parties, boundaries, and ISMS scope. Be clear about services, sites, assets, and exclusions.
Assign accountability, establish an information-security policy, set objectives, and make sure the ISMS is supported at the right level of the organisation.
Use a repeatable method to identify risks, assess their significance, select treatments, assign owners, and accept residual risk through appropriate governance.
Choose safeguards that address identified risks. Maintain a clear rationale for applicable controls and how they are implemented, monitored, or excluded.
Support competence and awareness, manage documented information, communicate expectations, and ensure security practices operate in normal business activities.
Measure relevant performance, conduct internal audits, hold management reviews, address nonconformities, and improve the ISMS over time.
Evidence to organise
Assessment is helped by information that shows how the ISMS was designed and how it works in practice. The exact set of records will depend on your context and risk decisions.