Information is an Asset which, like other important business assets, has Value to an organization and consequently needs to be Suitably protected.
An “Information Security Management System” is that part of the overall management system, based on a business risk approach, to establish, implement, operate, monitor, review, maintain and improve information security. ISMS always follows Plan-Do-Check-Act (PDCA) methodology.
Define the clear boundaries of your ISMS.
Identify assets and implement Risk Treatment Plans.
Evaluate technical and non-technical environments.
Documentation of Statement of Applicability (SOA).
Information Security Awareness & Training for personnel.