[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-161707-105":53,"doc-detail-161707-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","information-security-internal-procedures-isoiec-270012022","Information Security internal procedures - ISO/IEC 27001:2022","","This document provides a structured table of content for an organization’s Information Security internal procedures aligned to ISO/IEC 27001:2022. It covers governance and organizational controls, including policies, roles and responsibilities, threat intelligence, asset inventory, access control, and information classification and transfer. It further details supplier, cloud, incident management, evidence collection, business continuity readiness, privacy and compliance, plus people and physical/technological control domains to support consistent operational implementation.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":11,"@type":70,"position":76},"https://docshare.wps.com/template/presentations/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/information-security-internal-procedures-isoiec-270012022/161707/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/information-security-internal-procedures-isoiec-270012022/161707.png","ImageObject",442,249,{"name":88,"@type":89},"Olivia Brown","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-19","2026-08-30",true,{"@type":98,"interactionType":99,"userInteractionCount":73},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"What main control areas are included in these information security internal procedures?","Question",{"text":108,"@type":109},"The table of content organizes procedures into Organizational controls (A5), People controls (A6), Physical controls (A7), and Technological controls (A8).","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"How do the procedures address access and information handling?",{"text":113,"@type":109},"They include topics such as access control, identity management, authentication information, classification and labeling of information, and information transfer.",{"name":115,"@type":106,"acceptedAnswer":116},"How is supplier, cloud, and incident management handled?",{"text":117,"@type":109},"The outline covers information security in supplier relationships and cloud services, and includes incident management planning, assessment, response, learning, and evidence collection.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},161707,1788108244,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":8,"category_name":11,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":73,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":135,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":125,"read_time":20},16904993612988,"https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd","[COMPANY LOGO]\nInformation Security\ninternal procedures\n[ORGANIZATION]\nVersion: [MONTH] 2023 [VERSION]\nApproved by management: NOT YET APPROVED\n\u000f\nTable of content\n\u0013 TOC \\o \"1-3\" \\b \"TOC\" \u0014Introduction\t\u0013 PAGEREF _Toc125635296 \\h \u00146\u0015\nBackground\t\u0013 PAGEREF _Toc125635297 \\h \u00146\u0015\nStructure\t\u0013 PAGEREF _Toc125635298 \\h \u00146\u0015\nOrganizational controls (A5)\t\u0013 PAGEREF _Toc125635299 \\h \u00147\u0015\n5.1 Policies for information security\t\u0013 PAGEREF _Toc125635300 \\h \u00147\u0015\n5.2 Information security roles and responsibilities\t\u0013 PAGEREF _Toc125635301 \\h \u00147\u0015\n5.3 Segregation Of duties\t\u0013 PAGEREF _Toc125635302 \\h \u00147\u0015\n5.4 Management responsibilities\t\u0013 PAGEREF _Toc125635303 \\h \u00147\u0015\n5.5 Contact with authorities\t\u0013 PAGEREF _Toc125635304 \\h \u00147\u0015\n5.6 Contact with special interest groups\t\u0013 PAGEREF _Toc125635305 \\h \u00147\u0015\n5.7 Threat intelligence\t\u0013 PAGEREF _Toc125635306 \\h \u00148\u0015\n5.8 Information security in project management\t\u0013 PAGEREF _Toc125635307 \\h \u00148\u0015\n5.9 Inventory of information and other associated assets\t\u0013 PAGEREF _Toc125635308 \\h \u00148\u0015\n5.10 Acceptable use of information and other associated assets\t\u0013 PAGEREF _Toc125635309 \\h \u00149\u0015\n5.11 Return of assets\t\u0013 PAGEREF _Toc125635310 \\h \u00149\u0015\n5.12 Classification of information\t\u0013 PAGEREF _Toc125635311 \\h \u001410\u0015\n5.13 Labelling of information\t\u0013 PAGEREF _Toc125635312 \\h \u001410\u0015\n5.14 Information transfer\t\u0013 PAGEREF _Toc125635313 \\h \u001410\u0015\n5.15 Access control\t\u0013 PAGEREF _Toc125635314 \\h \u001410\u0015\n5.16 Identity management\t\u0013 PAGEREF _Toc125635315 \\h \u001411\u0015\n5.17 Authentication information\t\u0013 PAGEREF _Toc125635316 \\h \u001411\u0015\n5.18 Access rights\t\u0013 PAGEREF _Toc125635317 \\h \u001411\u0015\n5.19 Information security in supplier relationships\t\u0013 PAGEREF _Toc125635318 \\h \u001412\u0015\n5.20 Addressing information security within supplier agreements\t\u0013 PAGEREF _Toc125635319 \\h \u001412\u0015\n5.21 Managing information security in the information and communication technology (ICT) supply chain\t\u0013 PAGEREF _Toc125635320 \\h \u001412\u0015\n5.22 Monitoring, review and change management of supplier services\t\u0013 PAGEREF _Toc125635321 \\h \u001412\u0015\n5.23 Information security for use of cloud services\t\u0013 PAGEREF _Toc125635322 \\h \u001412\u0015\n5.24 Information security incident management planning and preparation\t\u0013 PAGEREF _Toc125635323 \\h \u001413\u0015\n5.25 Assessment and decision on information security events\t\u0013 PAGEREF _Toc125635324 \\h \u001413\u0015\n5.26 Response to information security incidents\t\u0013 PAGEREF _Toc125635325 \\h \u001413\u0015\n5.27 Learning from information security incidents\t\u0013 PAGEREF _Toc125635326 \\h \u001413\u0015\n5.28 Collection of evidence\t\u0013 PAGEREF _Toc125635327 \\h \u001414\u0015\n5.29 Information security during disruption\t\u0013 PAGEREF _Toc125635328 \\h \u001414\u0015\n5.30 ICT readiness for business continuity\t\u0013 PAGEREF _Toc125635329 \\h \u001414\u0015\n5.31 Legal, statutory, regulatory and contractual requirements\t\u0013 PAGEREF _Toc125635330 \\h \u001414\u0015\n5.32 Intellectual property rights\t\u0013 PAGEREF _Toc125635331 \\h \u001414\u0015\n5.33 Protection of records\t\u0013 PAGEREF _Toc125635332 \\h \u001414\u0015\n5.34 Privacy and protection of personal identifiable information (PII)\t\u0013 PAGEREF _Toc125635333 \\h \u001414\u0015\n5.35 Independent review of information security\t\u0013 PAGEREF _Toc125635334 \\h \u001415\u0015\n5.36 Compliance with policies, rules and standards for information security\t\u0013 PAGEREF _Toc125635335 \\h \u001415\u0015\n5.37 Documented operating procedures\t\u0013 PAGEREF _Toc125635336 \\h \u001415\u0015\nPeople controls (A6)\t\u0013 PAGEREF _Toc125635337 \\h \u001416\u0015\n6.1 Screening\t\u0013 PAGEREF _Toc125635338 \\h \u001416\u0015\n6.2 Terms and conditions of employment\t\u0013 PAGEREF _Toc125635339 \\h \u001416\u0015\n6.3 Information security awareness, education and training\t\u0013 PAGEREF _Toc125635340 \\h \u001416\u0015\n6.4 Disciplinary process\t\u0013 PAGEREF _Toc125635341 \\h \u001416\u0015\n6.5 Responsibilities after termination or change of employment\t\u0013 PAGEREF _Toc125635342 \\h \u001417\u0015\n6.6 Confidentiality or non-disclosure agreements\t\u0013 PAGEREF _Toc125635343 \\h \u001417\u0015\n6.7 Remote working\t\u0013 PAGEREF _Toc125635344 \\h \u001417\u0015\n6.8 Information security event reporting\t\u0013 PAGEREF _Toc125635345 \\h \u001418\u0015\nPhysical controls (A7)\t\u0013 PAGEREF _Toc125635346 \\h \u001419\u0015\n7.1 Physical security perimeters\t\u0013 PAGEREF _Toc125635347 \\h \u001419\u0015\n7.2 Physical entry\t\u0013 PAGEREF _Toc125635348 \\h \u001419\u0015\n7.3 Secu","cbCaidhVa0rxDbeZ","https://ap.wps.com/l/cbCaidhVa0rxDbeZ","docx",160181,39,"English","# Introduction\n## Background\n## Structure\n# Organizational controls (A5)\n## Policies for information security\n## Information security roles and responsibilities\n# People controls (A6)\n## Screening\n## Information security awareness, education and training\n# Physical controls (A7)\n## Physical security perimeters\n## Clear desk and clear screen\n# Technological controls (A8)\n## User endpoint devices\n## Protection against malware","[{\"question\":\"What main control areas are included in these information security internal procedures?\",\"answer\":\"The table of content organizes procedures into Organizational controls (A5), People controls (A6), Physical controls (A7), and Technological controls (A8).\"},{\"question\":\"How do the procedures address access and information handling?\",\"answer\":\"They include topics such as access control, identity management, authentication information, classification and labeling of information, and information transfer.\"},{\"question\":\"How is supplier, cloud, and incident management handled?\",\"answer\":\"The outline covers information security in supplier relationships and cloud services, and includes incident management planning, assessment, response, learning, and evidence collection.\"}]","Information Security internal procedures - ISO/IEC 27001:2022 | DOCX"]