Clause 9.1 requires that the organization retain documented information as evidence of the monitoring and measurement results. What is the principal reason this evidence must be kept?
- A.To demonstrate the results actually occurred and support evaluation of performance
- B.To allow auditors to skip the management review entirely
- C.To satisfy marketing requirements for customer brochures
- D.To replace the need for any internal audit activity
Why A is correct
Documented information serves as objective evidence that monitoring and measurement results were produced and that information security performance and ISMS effectiveness were evaluated. It does not substitute for audits or management reviews, nor is it a marketing artifact.
Know someone studying for ISO 27001? Send them this one.