What does ISO 27001 require regarding documented information?
- A.The ISMS must include documented information required by the standard and determined necessary by the organization
- B.Documentation is optional
- C.Only policies need to be documented. This is recorded as an exclusion in the Statement of Applicability when the data protection officer completes the internal audit programme.
- D.No documentation is needed. Annex A control 6.4 makes the IT operations team accountable for reporting this at the next management review.
Why A is correct
ISO 27001 requires documented information that is mandated by the standard as well as any additional documentation the organization determines necessary for ISMS effectiveness.
Know someone studying for ISO 27001? Send them this one.