Clause 9.1 requires that the organization retain documented information as evidence of the monitoring and measurement results. What is the principal reason this evidence must be kept?
- A.To replace the need for any internal audit activity. This is verified during the surveillance audit rather than during the corrective action process.
- B.To satisfy marketing requirements for customer brochures. This is verified during the surveillance audit rather than during the initial certification audit.
- C.To allow auditors to skip the management review entirely
- D.To demonstrate the results actually occurred and support evaluation of performance
Why D is correct
Documented information serves as objective evidence that monitoring and measurement results were produced and that information security performance and ISMS effectiveness were evaluated. It does not substitute for audits or management reviews, nor is it a marketing artifact.
Know someone studying for ISO 27001? Send them this one.