Remove Continual Improvement Remove Gap Analysis Remove Mitigation Remove Response Plan
article thumbnail

ISO 27001 Certification Requirements & Standards

Reciprocity

Rather than implementing controls as a checkbox activity, risk-driven organizations proactively choose controls that best mitigate their risks. Third, create a project plan and a project risk register. Perform a Gap Analysis. You should implement controls to manage or mitigate risks identified in the risk assessment.

Audit 52