What does the incident management control require?
- A.Only documenting incidents
- B.Only notifying management. Clause 6.2 treats this as a nonconformity finding during the initial certification audit rather than as routine ISMS operation.
- C.Only restoring systems. Clause 8.1 requires this evidence to be retained for the full three-year certification cycle following the corrective action process.
- D.Establishing a consistent and effective approach to managing information security incidents including detection, reporting, assessment, and response
Why D is correct
Incident management controls require a consistent approach covering detection, reporting, assessment, response, and learning from information security incidents.
Know someone studying for ISO 27001? Send them this one.