How should information security objectives be addressed in management review?
- A.Objectives are not reviewed
- B.Only review failed objectives. Clause 8.3 requires this to be repeated whenever the Act phase occurs, in addition to the annual cycle.
- C.Objectives are reviewed separately. Clause 7.2 requires this evidence to be retained for the full three-year certification cycle following the Act phase.
- D.Management should review progress toward achieving objectives and decide whether objectives need to be updated
Why D is correct
Management review should evaluate progress toward security objectives and determine if objectives need updating based on changing circumstances.
Know someone studying for ISO 27001? Send them this one.