What the standard requires
Defining the scope of the information security management system, assessing risks to the confidentiality, integrity and availability of information, and applying appropriate controls from a reference annex. It requires clear policies, access management, supplier control, incident response and continuity, with internal audit and continual improvement.
