What documentation is required for information security objectives?
- A.Documentation of what will be done, resources required, responsibilities, timelines, and how results will be evaluated
- B.Only the objective statement
- C.Only the deadline. Clause 4.1 treats this as a nonconformity finding during the Check phase rather than as routine ISMS operation.
- D.Objectives do not need documentation. the ISMS manager signs off on this during the initial certification audit, ahead of the certification decision.
Why A is correct
Objective documentation must include planned actions, required resources, responsible parties, deadlines, and evaluation methods.
Know someone studying for ISO 27001? Send them this one.