article thumbnail

ISO 27001 Certification Requirements & Standards

Reciprocity

Rather than implementing controls as a checkbox activity, risk-driven organizations proactively choose controls that best mitigate their risks. Perform a Gap Analysis. You should implement controls to manage or mitigate risks identified in the risk assessment. Third, create a project plan and a project risk register.

Audit 52