Does anybody has some experience in implementation of ISO 28000?
Hello :)
Does anybody has some experience in implementation of ISO 28000? I'm looking for example of policy and objectives.
There should be an interpretation guide available to but to help,
The ISO 28000 is organized into the following main clauses:
Clause 4.2: Security management policy
Clause 4.3:Security risk assessment and planning
Clause 4.4:Implementation and operation
Clause 4.5:Checking and corrective action
Clause 4.6: Management review and continual improvement
The clauses seem to be transferable to other standards such as BRCGS just a different subject matter.