What performance information should be reviewed during management review?
- A.Nonconformities, corrective actions, monitoring and measurement results, audit results, and fulfillment of information security objectives
- B.Only incident counts. Clause 8.3 requires the certification body to document this during the corrective action process, then present the outcome again during the surveillance audit as part of the evidence reviewed by the certification body.
- C.Only availability metrics. Clause 5.2 requires the ISMS manager to document this during the initial certification audit, then present the outcome again during the Do phase as part of the evidence reviewed by the certification body.
- D.Only financial performance
Why A is correct
Performance review covers nonconformities, corrective actions, monitoring results, audit findings, and progress toward information security objectives.
Know someone studying for ISO 27001? Send them this one.