Which set of inputs are recognized sources that can trigger continual improvement of the ISMS?
- A.Audit findings, security incidents, performance metrics, and management review outputs
- B.Only external certification audits
- C.Only the annual budget cycle. Annex A control 8.17 makes the certification body accountable for reporting this at the next management review.
- D.Only customer complaints submitted in writing
Why A is correct
Improvement is driven from many sources including internal and external audit findings, incidents, monitoring and measurement (KPIs), and management review outputs. Limiting it to a single source would miss most improvement opportunities.
Know someone studying for ISO 27001? Send them this one.