
Episode 23 — A.5.1–5.2 — Policies for InfoSec; Roles & responsibilities
A.5.1 requires establishing a set of information security policies that provide direction and support consistent with business objectives and relevant laws and regulations. For the exam, remember the ...
14 Okt 202515min

Episode 22 — Clause 9.3 + 10 — Management review; Nonconformity; Continual improvement
Clause 9.3 requires top management to conduct reviews at planned intervals to ensure the ISMS remains suitable, adequate, and effective. For exam purposes, recognize the mandatory inputs: changes in i...
14 Okt 202514min

Episode 21 — Clause 9.2 — Internal audit
Clause 9.2 establishes the internal audit as a formal, independent check on ISMS conformity and effectiveness. For the exam, remember that audits must be planned, implemented, and maintained with defi...
14 Okt 202515min

Episode 20 — Clause 9.1 — Monitoring, measurement, analysis & evaluation
Clause 9.1 requires organizations to determine what needs to be monitored and measured, the methods, the timing, the responsibility, and how results are analyzed and evaluated. For the exam, candidate...
14 Okt 202520min

Episode 19 — Clause 8.2 + 8.3 — Risk assessment & treatment in operations
Clauses 8.2 and 8.3 require conducting risk assessments at planned intervals and implementing risk treatment plans—bringing the methodology from Clause 6.1.2 and the planning from Clause 6.1.3 into th...
14 Okt 202514min

Episode 18 — Clause 8.1 — Operational planning and control
Clause 8.1 translates strategy into execution by requiring the organization to plan, implement, and control the processes needed to meet ISMS requirements, including criteria for processes and accepta...
14 Okt 202515min

Episode 17 — Clause 7.5 — Documented information
Clause 7.5 sets requirements for creating, updating, and controlling documented information necessary for the ISMS. The standard distinguishes between documents (living instructions and descriptions) ...
14 Okt 202515min

Episode 16 — Clause 7.3 + 7.4 — Awareness; Communication
Clause 7.3 requires organizations to ensure that people doing work under their control are aware of the information security policy, their contribution to ISMS effectiveness, and the implications of n...
14 Okt 202515min



















