Introduction to ISMS and ISO 27001:2022: Structure, PDCA, and Organizational Context — Learning with AI on ASI Biont

Introduction: Why ISMS Is Not About Paperwork, But About Business

Information security (IS) has ceased to be a task solely for the IT department. Today, a data leak or system failure can cost a company its reputation and millions. That is why the ISO 27001:2022 standard has become a global benchmark for building an Information Security Management System (ISMS). But how can you approach implementation systematically, without drowning in documents and losing focus on real threats? In this article, we will break down the key elements: the standard's structure, the PDCA cycle, and the importance of defining the organizational context. We will also explore how modern approaches, including AI-assisted learning, help accelerate preparation for certification.

Structure of ISO 27001:2022: From Context to Certification

The 2022 standard consists of 10 clauses and Annex A with 93 controls. Unlike the previous version, the emphasis has shifted to analyzing the context—external and internal factors affecting IS. Key clauses:

  • Clause 4. Context of the Organization — defines interested parties, their requirements, and the ISMS boundaries.
  • Clause 5. Leadership — requires top management commitment and an IS policy.
  • Clause 6. Planning — risk assessment (ISO 27005) and action planning.
  • Clause 7. Support — competence, awareness, documented information.
  • Clause 8. Operation — asset management, access control, change management, and incident management.
  • Clause 9. Performance Evaluation — internal audit and management review.
  • Clause 10. Improvement — corrective actions and continual improvement.

Annex A groups controls into four themes: organizational, people, physical, and technological. For example, access control covers IAM, RBAC, and MFA, while asset management requires inventory and classification.

The PDCA Cycle: How to Apply It in Practice

The "Plan-Do-Check-Act" (PDCA) model is the foundation of ISMS. Let's look at an implementation example:

Stage Actions Practical Example
Plan Define context, assess risks, develop IS policy and asset register Company "Alpha" identified a risk of leakage via remote access—planned MFA implementation
Do Implement measures: configure RBAC, train staff, install anti-malware Deployed a Privileged Access Management (PAM) system for administrators
Check Conduct internal audit, monitor incidents, analyze metrics Audit showed 20% of employees do not use MFA—adjusted training
Act Address non-conformities, update policies, conduct management review Updated the Risk Treatment Plan

The cycle repeats continuously. Without PDCA, ISMS becomes a static set of documents.

Organizational Context: The First Step to a Successful ISMS

Clause 4 of the standard requires defining:
- External context (laws, regulators, market conditions).
- Internal context (corporate culture, IT infrastructure, budget).
- Interested parties (clients, investors, government bodies).
- Requirements (GDPR, 152-FZ, contractual obligations).

Practical tip: Create a matrix of interested parties and their requirements. For example, for a data center, physical security (secured zones, video surveillance) and environmental safety (cooling systems, backup power) are critical. Without this context, risk assessment will be incomplete.

Information Security Policy: Document Hierarchy

The standard requires at least 6 mandatory documents, but in practice there are dozens. The hierarchy looks like this:

  1. IS Policy — top-level document (approved by top management).
  2. Procedures — e.g., access management, change management.
  3. Plans — risk treatment plan, BCM plan.
  4. Registers and Logs — asset register, risk register, incident log.

An IS policy template should include: objectives, principles, roles and responsibilities, references to related policies (e.g., policy

← All posts

Comments