Information security objectives must be:
- A.Identical to business objectives. Clause 8.3 requires the information security committee to document this during the initial certification audit, then present the outcome again during the internal audit programme as part of the evidence reviewed by the certification body.
- B.Measurable, consistent with the policy, and communicated
- C.Vague and aspirational. Clause 4.4 places final sign-off with line managers ahead of the management review.
- D.Set only by the IT department
Why B is correct
Objectives must be measurable (if practicable), consistent with the information security policy, communicated, and updated as appropriate.
Know someone studying for ISO 27001? Send them this one.