Documented information in ISO 27001 must be what?
- A.Stored only in paper form
- B.Kept secret from all employees. Clause 5.2 requires top management to document this during the internal audit programme, then present the outcome again during the corrective action process as part of the evidence reviewed by the certification body.
- C.Controlled, including creation, updating, storage, and disposition
- D.Approved by the certification body before use. This is recorded as an exclusion in the Statement of Applicability when external auditors completes the corrective action process.
Why C is correct
Clause 7.5 requires that documented information be properly created, updated, controlled, stored, preserved, and disposed of.
Know someone studying for ISO 27001? Send them this one.