Viewee
Start free
Pricing
Sign in
← Legal and assurance

Requirements

RequirementWhat it means for VieweeOwner (Instinct / Alex+Cain / External assessor)EffortStatusEvidence neededSource URL
Use ISO/IEC 27001:2022 and Amendment 1:2024Build an ISMS to the current edition and consider whether climate change is a relevant issue and whether interested parties have climate-related requirements.Alex+CainMDo nowStandards register; context/interested-party analysishttps://www.iso.org/standard/88435.html
Define ISMS context and scope (clauses 4.1-4.4)Document internal/external issues, interested parties and requirements, interfaces/dependencies, and the scope covering people, marketing site, SaaS app, internal outreach admin, development and suppliers.Alex+CainHDo now; refine with architectureContext analysis, interested-party register, scope statement and process maphttps://www.iso.org/standard/27001
Leadership, policy and assigned roles (clause 5)Founders must approve policy, integrate the ISMS into work, provide resources and assign accountable security roles.Alex+CainMDo nowApproved information security policy, role/RACI, meeting decisionshttps://www.iso.org/standard/27001
Risk assessment method (6.1.2)Define repeatable risk criteria, likelihood/impact and acceptance; identify owners and assess confidentiality, integrity and availability risks.Alex+CainHDo nowRisk methodology, risk register and approvalshttps://www.iso.org/standard/27001
Risk treatment and Statement of Applicability (6.1.3)Select controls, compare with Annex A, justify inclusions/exclusions, assign actions and accept residual risks.Alex+CainHDo now; validate before auditRisk treatment plan, SoA, residual-risk acceptanceshttps://www.iso.org/standard/27001
Security objectives and plans (6.2)Set measurable objectives with owner, resources, timing and evaluation method.Alex+CainMDo nowObjectives/KPIs and review recordshttps://www.iso.org/standard/27001
Plan controlled ISMS changes (6.3)Plan material ISMS changes rather than making them ad hoc.Alex+CainLDo nowChange records and impact assessmentshttps://www.iso.org/standard/27001
Resources, competence and awareness (clause 7)Provide resources; ensure people/contractors are competent and understand policy, responsibilities and consequences.Alex+CainMDo now and ongoingTraining/competence records, onboarding and acknowledgementshttps://www.iso.org/standard/27001
Communication and documented information (7.4-7.5)Define what/when/with whom to communicate and control creation, approval, versioning, access, retention and disposal of ISMS records.InstinctMDo nowDocument-control procedure, register, approvals and versionshttps://www.iso.org/standard/27001
Operational planning and control (8.1)Operate planned processes, control changes and outsourced processes, and retain evidence.Alex+CainHNeeds operating product for full evidenceRunbooks, tickets, change/release records and supplier controlshttps://www.iso.org/standard/27001
Perform and update risk assessments/treatment (8.2-8.3)Reassess at planned intervals and after significant change; implement treatment plan and retain results.Alex+CainMDo now then ongoingDated assessments, treatment status and change-trigger reviewshttps://www.iso.org/standard/27001
Monitor, measure, analyse and evaluate (9.1)Choose security metrics, methods, owners and frequency; evaluate control and ISMS effectiveness.Alex+CainMNeeds operating evidenceMetrics dashboard, monitoring reports, trend/actionshttps://www.iso.org/standard/27001
Internal audit programme (9.2)Audit conformity and effective implementation at planned intervals using objective, impartial auditors; report and track results.External assessorHAfter ISMS operatesAudit programme, plans, reports, findings and closure evidencehttps://www.iso.org/standard/27001
Management review (9.3)Founders review changes, performance, audit results, objectives, risks, opportunities and improvement decisions at planned intervals.Alex+CainMAfter operating cycleAgenda, inputs, minutes, decisions and actionshttps://www.iso.org/standard/27001
Nonconformity, corrective action and improvement (clause 10)React, correct, analyse root cause, prevent recurrence, check effectiveness and continually improve suitability and effectiveness.Alex+CainMAfter operating cycleCorrective-action log, root cause and effectiveness reviewshttps://www.iso.org/standard/27001
Annex A organisational controlsAddress policies, roles, segregation, threat intelligence, projects, assets, acceptable use, return of assets, classification/transfer, access, identity/authentication, suppliers/cloud, incidents/evidence, continuity, legal/privacy, records and independent review.Alex+CainHDo now; operating evidence laterSoA-linked policies, registers, contracts, incident exercises and reviewshttps://www.iso.org/standard/27001
Annex A people controlsScreening proportionate to role; terms, awareness, disciplinary process, exit obligations, confidentiality, remote working and event reporting.Alex+CainMBefore hiring/contractorsContracts, NDA/confidentiality, onboarding/offboarding, traininghttps://www.iso.org/standard/27001
Annex A physical controlsDefine physical security appropriate to remote founders and any offices, including equipment, clear screen, disposal and off-premises assets.Alex+CainMDo nowRemote-working/device policy, asset handling and disposal recordshttps://www.iso.org/standard/27001
Annex A technological controlsImplement endpoint, privilege, access, MFA, capacity, malware, vulnerabilities, configuration, deletion/masking/DLP, backup, resilience, logging/monitoring, time sync, network/web/email security, cryptography, secure SDLC/testing, outsourced development, environment separation, change and test-data controls.Alex+CainHDesign now; prove after build/liveArchitecture, IaC, CI/CD scans, logs, test results, backups/restores, vulnerability and patch evidencehttps://www.iso.org/standard/27001
Independent vulnerability assessment and penetration testingRisk-based security testing should cover internet-facing app/API and cloud configuration before launch and after material change; use competent independent testing where customer risk/assurance requires it.External assessorHBefore production launchScope, rules of engagement, report, remediation and retesthttps://www.iso.org/standard/27001
Select UKAS-accredited certification bodyIf seeking certification, use a competent certification body accredited for ISO/IEC 27001; expect Stage 1, Stage 2 and surveillance. Do not describe Viewee as certified beforehand.External assessorHLater, after operating evidenceUKAS scope check, proposal, audit plan, reports and certificatehttps://www.ukas.com/accreditation/sectors/digital/info-sec/