
Struggling to Structure Policies for ISO 27001 Implementation
ISO27001ISMSInformationSecurityPolicyStructureCybersecurity
The author of the Reddit post mentions that they are implementing the ISO 27001 standard for a client and have already drafted several documents, including the ISMS objectives, the ISMS scope, roles and responsibilities, and various policies and procedures. They are wondering how to structure these documents and whether they should be included in an ISP (PSSI in French). The author expresses confusion about the length and content of the ISP, with some advising to include only the first three elements, while others suggest a longer document including policies such as the Clean Desk.