Management-system focus
The standard is not merely a technical control list. It establishes governance, scope, leadership, risk assessment, treatment, resources, competence, operation, measurement, internal audit, management review, and improvement.
Risk treatment
Organizations identify information-security risk, choose treatment, determine necessary controls, document applicability, and preserve evidence that the management system operates.
Certification
Independent certification can provide assurance that the management system meets the standard within a defined scope. Certification does not mean that no security incident can occur.
Continuous improvement
Audits, monitoring, corrective action, changing risk, business change, and management review should drive ongoing improvement rather than one-time compliance.
Certification relevance
This subject appears in or supports the following certification bodies of knowledge: