Strategic Elements

  1. Scope of the ISMS
  2. Strategic issues and directions
  3. Legal and regulatory aspects
  4. Needs scale
  5. Security needs
  6. Sources of threats

1) Security Rules

1. Organization

  1. Security policy
  2. Security organization
  3. Information‑security risk management
  4. Security and lifecycle management
  5. Assurance and certification

2. Implementation

  1. Human aspects
  2. Business continuity planning
  3. Incident management
  4. Awareness and training
  5. Operations
  6. Physical and environmental aspects

3. Technical

  1. Identification / authentication
  2. Logical access control
  3. Logging

2) Action Plan

  1. Business Continuity Plan / Disaster Recovery Plan (BCP/DRP)
  2. Monitoring and alerting
  3. Backups and environment management
  4. Equipment management
  5. Flow isolation
  6. Access management
  7. Antivirus policy
  8. Supplier management and IT charter
  9. Roadmap

==Strategic Elements==