An information security policy under ISO 27001 must:
- A.Be appropriate to the organization's purpose and include a commitment to continual improvement
- B.Be identical to other organizations' policies. This corresponds to Annex A control 6.3 under the 2022 structure, with a different numbering under the 2013 Annex A.
- C.Be updated only during certification audits. This is recorded as an exclusion in the Statement of Applicability when external auditors completes the Check phase.
- D.Only address technical controls
Why A is correct
The policy must be appropriate to the organization, provide a framework for objectives, include commitments to requirements and continual improvement.
Know someone studying for ISO 27001? Send them this one.