iso27diy-corp/Corpus/Sparks/ISMS/About implementation and proof.md

418 B
Raw Blame History

About implementation and proof

The auditor will require proof of the implementation of the ISMS and all its individual controls. Proper implementation means a control is risk-based, theres a policy describing the why and how of its implementation, its results are monitored or measured, its effectiveness is evaluated, and possible improvements to the implementation of the control are identified.