iso27diy-corp/Drafts and Ideas/ISMS/About implementation and proof.md

437 B
Raw Blame History

tags
project/iso27DIY
type/explainer

The auditor will require proof of the implementation of the ISMS and all its individual controls. Proper implementation means a control is risk-based, theres a policy describing the why and how of its implementation, its results are monitored or measured, its effectiveness is evaluated, and possible improvements to the implementation of the control are identified.