1. Organizational Context
1. Governance and Management
2. Leadership and Commitment
2. Risk Assessment and Treatment
3. Risk Assessment and Treatment
3. Information Security Controls
4. Information Security Objectives
6. Awareness and Training
5. Human Resource Security
8. Operational Planning and Control
9. Performance Evaluation
10. Continuous Improvement
8. Physical and Environmental Security
11. Documentation and Record Keeping
12. Compliance and Legal Requirements
11. Business Continuity Management