A bank proposes outsourcing its entire core banking platform to a single cloud provider. Before signing, which Clause 8 activity is most directly required because this is a significant proposed change to how a critical process operates?
- A.Conducting the next annual management review early
- B.Updating the marketing collateral about the bank's security
- C.Performing an information security risk assessment for the proposed change under Clause 8.2
- D.Re-issuing all employee awareness certificates
Why C is correct
Clause 8.2 requires risk assessments when significant changes are proposed or occur. Outsourcing the core banking platform is a significant proposed change, so a risk assessment is required before the decision, feeding the control of the planned change under Clause 8.1.
Know someone studying for ISO 27001? Send them this one.