Description
This National Standard gives guidelines for organizational information security standards and information security management practices including the selection, implementation and management of controls taking into consideration the organization’s information security risk environments.
TABLE OF CONTENTS
| Content | Page |
| 1 Scope | 1 |
| 2 Normative references | 1 |
| 3 Terms and definitions | 1 |
| 4 Context of the organization | 1 |
| 5 Leadership | 2 |
| 6 Planning | 3 |
| 7 Support | 5 |
| 8 Operation | 7 |
| 9 Performance evaluation | 8 |
| 10 Improvement | 10 |
| Annex A (Normative) | 11 |

