1. Context of the Organization
2. Leadership and Commitment
3. Risk Assessment and Treatment
4. Information Security Objectives
6. Communication and Awareness
7. Performance Evaluation
8. Continuous Improvement
9. Documentation and Record Keeping
10. Compliance and Legal Requirements