
Episode 7 — Clause 4.4 — ISMS processes and interactions
Clause 4.4 elevates the ISMS from documentation to a functioning management system by requiring defined processes and their interactions. For exam candidates, this means recognizing that ISO 27001 dem...
14 Okt 202515min

Episode 6 — Clause 4.3 — Determining ISMS scope
Clause 4.3 defines one of the most critical early deliverables in ISO 27001 implementation: the formal ISMS scope. The scope establishes the boundaries within which controls will operate, outlining th...
14 Okt 202514min

Episode 5 — Clause 4.1 + 4.2
Clause 4.1 requires understanding the organization’s context—internal and external factors that influence the ISMS’s purpose and outcomes. Clause 4.2 extends this by mandating identification of intere...
14 Okt 202514min

Episode 4 — 27002 Attributes & the SoA
ISO 27002:2022 introduced a new attribute model to help organizations slice and categorize controls in multiple ways. Each control now includes attributes such as control type, information security pr...
14 Okt 202516min

Episode 3 — What Changed
The 2022 revision of ISO 27001 and 27002 modernized the framework to reflect today’s digital threat landscape. The control set was condensed from 114 to 93 by merging overlaps and aligning to four the...
14 Okt 202516min

Episode 2 — ISMS & PDCA in Practice
The ISMS is more than documentation; it is a governance framework built on the Plan-Do-Check-Act (PDCA) cycle that embeds continual improvement into security operations. The “Plan” stage defines conte...
14 Okt 202517min

Episode 1 — Orientation & Outcomes
ISO 27001 certification begins with understanding the broader ISO 27000 family of standards that form the foundation for information security management. ISO 27000 provides vocabulary and principles; ...
14 Okt 202515min



















