1. Context of the Organization
2. Leadership and Commitment
3. Risk Assessment and Treatment
4. Information Security Objectives
6. Competence and Awareness
8. Documentation and Control of Documents
9. Operational Planning and Control
10. Performance Evaluation
11. Nonconformity and Corrective Action
12. Continual Improvement