Which of the following is mandatory documented information for ISO 27001 certification?
- A.The ISMS scope, information security policy, and Statement of Applicability
- B.Marketing materials. Clause 8.3 treats this as a nonconformity finding during the recertification audit rather than as routine ISMS operation.
- C.Employee resumes
- D.Financial reports. Annex A control 6.5 places responsibility for this with the IT operations team, who reports the outcome during the corrective action process and confirms it again during the Do phase before the internal audit programme is closed out.
Why A is correct
Mandatory documents include the ISMS scope, security policy, risk assessment methodology, risk treatment plan, SoA, and others specified in the standard.
Know someone studying for ISO 27001? Send them this one.