An organization wishes to demonstrate to an auditor that its operational processes were carried out as planned over the past year. Under Clause 8.1, what is the most appropriate form of evidence?
- A.Verbal assurances from the CISO with no records
- B.Documented information such as logs, records and outputs generated during the operation of the processes
- C.A single screenshot of the security policy
- D.The marketing brochure describing the ISMS
Why B is correct
Clause 8.1 requires keeping documented information to have confidence that processes were carried out as planned. Operational records, logs and outputs are the evidence that demonstrates conformant execution to an auditor.
Know someone studying for ISO 27001? Send them this one.