| Requirement | What it means for Viewee | Owner (Instinct / Alex+Cain / External assessor) | Effort | Status | Evidence needed | Source URL |
|---|
| Use ISO/IEC 27001:2022 and Amendment 1:2024 | Build an ISMS to the current edition and consider whether climate change is a relevant issue and whether interested parties have climate-related requirements. | Alex+Cain | M | Do now | Standards register; context/interested-party analysis | https://www.iso.org/standard/88435.html |
| Define ISMS context and scope (clauses 4.1-4.4) | Document internal/external issues, interested parties and requirements, interfaces/dependencies, and the scope covering people, marketing site, SaaS app, internal outreach admin, development and suppliers. | Alex+Cain | H | Do now; refine with architecture | Context analysis, interested-party register, scope statement and process map | https://www.iso.org/standard/27001 |
| Leadership, policy and assigned roles (clause 5) | Founders must approve policy, integrate the ISMS into work, provide resources and assign accountable security roles. | Alex+Cain | M | Do now | Approved information security policy, role/RACI, meeting decisions | https://www.iso.org/standard/27001 |
| Risk assessment method (6.1.2) | Define repeatable risk criteria, likelihood/impact and acceptance; identify owners and assess confidentiality, integrity and availability risks. | Alex+Cain | H | Do now | Risk methodology, risk register and approvals | https://www.iso.org/standard/27001 |
| Risk treatment and Statement of Applicability (6.1.3) | Select controls, compare with Annex A, justify inclusions/exclusions, assign actions and accept residual risks. | Alex+Cain | H | Do now; validate before audit | Risk treatment plan, SoA, residual-risk acceptances | https://www.iso.org/standard/27001 |
| Security objectives and plans (6.2) | Set measurable objectives with owner, resources, timing and evaluation method. | Alex+Cain | M | Do now | Objectives/KPIs and review records | https://www.iso.org/standard/27001 |
| Plan controlled ISMS changes (6.3) | Plan material ISMS changes rather than making them ad hoc. | Alex+Cain | L | Do now | Change records and impact assessments | https://www.iso.org/standard/27001 |
| Resources, competence and awareness (clause 7) | Provide resources; ensure people/contractors are competent and understand policy, responsibilities and consequences. | Alex+Cain | M | Do now and ongoing | Training/competence records, onboarding and acknowledgements | https://www.iso.org/standard/27001 |
| Communication and documented information (7.4-7.5) | Define what/when/with whom to communicate and control creation, approval, versioning, access, retention and disposal of ISMS records. | Instinct | M | Do now | Document-control procedure, register, approvals and versions | https://www.iso.org/standard/27001 |
| Operational planning and control (8.1) | Operate planned processes, control changes and outsourced processes, and retain evidence. | Alex+Cain | H | Needs operating product for full evidence | Runbooks, tickets, change/release records and supplier controls | https://www.iso.org/standard/27001 |
| Perform and update risk assessments/treatment (8.2-8.3) | Reassess at planned intervals and after significant change; implement treatment plan and retain results. | Alex+Cain | M | Do now then ongoing | Dated assessments, treatment status and change-trigger reviews | https://www.iso.org/standard/27001 |
| Monitor, measure, analyse and evaluate (9.1) | Choose security metrics, methods, owners and frequency; evaluate control and ISMS effectiveness. | Alex+Cain | M | Needs operating evidence | Metrics dashboard, monitoring reports, trend/actions | https://www.iso.org/standard/27001 |
| Internal audit programme (9.2) | Audit conformity and effective implementation at planned intervals using objective, impartial auditors; report and track results. | External assessor | H | After ISMS operates | Audit programme, plans, reports, findings and closure evidence | https://www.iso.org/standard/27001 |
| Management review (9.3) | Founders review changes, performance, audit results, objectives, risks, opportunities and improvement decisions at planned intervals. | Alex+Cain | M | After operating cycle | Agenda, inputs, minutes, decisions and actions | https://www.iso.org/standard/27001 |
| Nonconformity, corrective action and improvement (clause 10) | React, correct, analyse root cause, prevent recurrence, check effectiveness and continually improve suitability and effectiveness. | Alex+Cain | M | After operating cycle | Corrective-action log, root cause and effectiveness reviews | https://www.iso.org/standard/27001 |
| Annex A organisational controls | Address policies, roles, segregation, threat intelligence, projects, assets, acceptable use, return of assets, classification/transfer, access, identity/authentication, suppliers/cloud, incidents/evidence, continuity, legal/privacy, records and independent review. | Alex+Cain | H | Do now; operating evidence later | SoA-linked policies, registers, contracts, incident exercises and reviews | https://www.iso.org/standard/27001 |
| Annex A people controls | Screening proportionate to role; terms, awareness, disciplinary process, exit obligations, confidentiality, remote working and event reporting. | Alex+Cain | M | Before hiring/contractors | Contracts, NDA/confidentiality, onboarding/offboarding, training | https://www.iso.org/standard/27001 |
| Annex A physical controls | Define physical security appropriate to remote founders and any offices, including equipment, clear screen, disposal and off-premises assets. | Alex+Cain | M | Do now | Remote-working/device policy, asset handling and disposal records | https://www.iso.org/standard/27001 |
| Annex A technological controls | Implement endpoint, privilege, access, MFA, capacity, malware, vulnerabilities, configuration, deletion/masking/DLP, backup, resilience, logging/monitoring, time sync, network/web/email security, cryptography, secure SDLC/testing, outsourced development, environment separation, change and test-data controls. | Alex+Cain | H | Design now; prove after build/live | Architecture, IaC, CI/CD scans, logs, test results, backups/restores, vulnerability and patch evidence | https://www.iso.org/standard/27001 |
| Independent vulnerability assessment and penetration testing | Risk-based security testing should cover internet-facing app/API and cloud configuration before launch and after material change; use competent independent testing where customer risk/assurance requires it. | External assessor | H | Before production launch | Scope, rules of engagement, report, remediation and retest | https://www.iso.org/standard/27001 |
| Select UKAS-accredited certification body | If seeking certification, use a competent certification body accredited for ISO/IEC 27001; expect Stage 1, Stage 2 and surveillance. Do not describe Viewee as certified beforehand. | External assessor | H | Later, after operating evidence | UKAS scope check, proposal, audit plan, reports and certificate | https://www.ukas.com/accreditation/sectors/digital/info-sec/ |