1. Factors Influencing Information Security
Has the organization evaluated internal and external factors influencing information security, including stakeholder expectations, regulatory obligations, customer requirements, and the potential impact of climate change?
2. Stakeholder Expectations & Obligations
Has the organization determined which stakeholder expectations, legal obligations, and relevant requirements must be addressed by the Information Security Management System (ISMS)?
3. Establishing ISMS Scope
Has the organization clearly established the scope of its Information Security Management System, including organizational boundaries, outsourced activities, partner involvement, and any climate change–related considerations?
4. Defining Required ISMS Processes
Has the organization defined and implemented the necessary processes, roles, responsibilities, and continual improvement mechanisms required to ensure the ongoing effectiveness of the Information Security Management System?
5. Policies, Objectives & Communication
Has your organization established an information security policy and defined objectives that align with its strategic direction, and have these been effectively communicated to employees and relevant stakeholders?
6. Roles, Responsibilities & Authorities
Have roles, responsibilities, and authorities been clearly defined and assigned to ensure effective management, operation, and reporting of the information security management system (ISMS)?
7. Achieving Objectives & Personal Duties
Has leadership ensured that a structured plan exists to achieve information security objectives, and that personnel understand their importance and their individual responsibilities in supporting them?
8. Risks and Opportunities Identification
Has the organization identified key risks and opportunities that may impact the effectiveness of the Information Security Management System (ISMS), and established appropriate actions to address them?
9. Repeatable Risk Assessment Methodology
Is there a defined, consistent, and repeatable methodology for conducting information security risk assessments, including evaluation of risk likelihood and potential impact?
10. Risk Acceptance Criteria & Priorities
Have risk acceptance criteria been formally established, and are identified risks evaluated and prioritized according to these criteria?
11. Assigned Risk Owners
Are risk owners assigned for each identified risk, with defined responsibilities to review, approve, and oversee risk treatment activities?
12. Controls Verification (Annex A Alignment)
Have suitable risk treatment options and security controls been selected and implemented, and verified against ISO/IEC 27001 Annex A to ensure no applicable controls have been overlooked?
13. Statement of Applicability (SoA)
- identifies selected security controls,
- specifies applicable Annex A controls,
- justifies inclusion or exclusion decisions,
- documents any additional controls implemented, and
- confirms implementation status?
14. Risk Treatment Plan & Residual Risks
Is a formal risk treatment plan maintained, and are any residual risks explicitly reviewed and accepted by authorized management?
15. Measurable ISMS Objectives
Have measurable ISMS objectives been defined, communicated, and aligned with organizational information security goals?
16. Structured Change Management
Does the organization follow a controlled and structured process to plan, evaluate, and manage changes affecting the ISMS?
17. Resource Provisioning
Are adequate resources—including personnel, technology, infrastructure, and operational environment—provided to establish, operate, maintain, and continually improve the ISMS?
18. Competency, Awareness & Training
- their responsibilities,
- the information security policy, and
- the significance of their contributions to ISMS effectiveness?
19. Documented Information Control
Is documented information properly created, maintained, protected, and controlled, and are internal and external communication requirements clearly defined and managed?
20. Integrating Risks into Operations
Have risk and opportunity management actions been integrated into operational processes, and are these processes consistently executed as planned?
21. Controlling Planned & Unplanned Changes
When organizational or system changes occur, are they planned, reviewed, and controlled to minimize potential impacts on information security?
22. Outsourcing & Third-Party Governance
Are outsourced activities and third-party service providers effectively governed to ensure compliance with established information security requirements?
23. Periodic Risk Assessments
Are information security risks periodically assessed, with documented records maintained for risk evaluations, treatment decisions, and management approvals?
24. Monitoring & Measurement Criteria
Have measurement criteria been established, including what is monitored, the methods used, the frequency of measurement, responsible personnel, and the maintenance of documented results?
25. Independent Internal Audits
Are internal audits conducted by independent and impartial auditors, with findings properly documented and communicated to management?
26. Resolving Audit & Monitoring Nonconformities
Is a formal process established to identify, manage, and resolve issues or nonconformities detected through monitoring activities or audit outcomes?
27. Qualified Audit Reports
Are internal audits performed objectively by qualified auditors, and are audit results recorded and reported to relevant management stakeholders?
28. Performance Records Retention
Has the organization defined monitoring and measurement requirements, including responsibilities, timing, methodologies, and retention of performance records?
29. Corrective Actions & Root Cause Analysis
When an issue occurs, do you take corrective action, identify and address the root cause, verify the effectiveness of the fix, and document the outcome?