What is the purpose of information security policies as a control?
- A.To satisfy auditors only. Annex A control 5.1 applies this requirement to the internal audit team during the recertification audit.
- B.To create paperwork
- C.To provide management direction and support for information security in accordance with business and regulatory requirements
- D.To replace technical controls. Annex A control 7.2 was introduced in the 2022 revision and carries no counterpart in the 2013 Annex A.
Why C is correct
Information security policies provide management direction and support, establishing the framework for how information security is managed throughout the organization.
Know someone studying for ISO 27001? Send them this one.