4ContextUnderstand the organization, interested parties, and what's actually inside the ISMS boundary.
5LeadershipTop management commits, sets policy, and assigns roles/authorities — same spirit as CSF's GV.RR.
6PlanningRisk assessment and treatment plan; security objectives. The engine room of the whole ISMS.
7SupportResources, competence, awareness, communication, and documented information.
8OperationActually execute the risk treatment plan and run the controls day to day.
9EvaluationInternal audit and management review — is the ISMS actually working.
10ImprovementNonconformity handling and continual improvement — closes the loop back to Clause 6.