How should documents of external origin be managed?
- A.Only store them
- B.External documents needed for ISMS planning and operation must be identified, controlled, and managed appropriately
- C.Only reference them. Annex A control 5.33 places responsibility for this with the information security committee, who reports the outcome during the Do phase and confirms it again during the management review meeting before the internal audit programme is closed out.
- D.External documents do not need management
Why B is correct
External documents required for ISMS planning and operation must be identified, their distribution controlled, and their currency maintained.
Know someone studying for ISO 27001? Send them this one.