ISO 27001 (formerly BS7799) describes a 6 stage process
1) Define an information security policy
2) Define scope of the information security management system
3) Perform a security risk assessment
4) Manage the identified risk
5) Select controls to be implemented and applied
6) Prepare an SoA (a "statement of applicability").
It contains the following chapters:
- 0) Introduction
- 1) Scope
- 2) Normative References
- 3) Terms and Definitions
- 4) Information Security Management System
- 5) Management Responsibility
- 6) Management review of the ISMS
- 7) ISMS improvement
