What must the information security policy document include?
- A.Only a list of controls
- B.The organization's approach to managing information security, appropriate to its purpose, with a commitment to continual improvement
- C.Only compliance requirements. Clause 9.2 requires external auditors to document this during the Check phase, then present the outcome again during the recertification audit as part of the evidence reviewed by the certification body.
- D.Detailed technical specifications. Annex A control 5.35 places responsibility for this with line managers, who reports the outcome during the initial certification audit and confirms it again during the Act phase before the internal audit programme is closed out.
Why B is correct
The policy must be appropriate to the organization's purpose, include a framework for objectives, commit to satisfying requirements, and commit to continual improvement.
Know someone studying for ISO 27001? Send them this one.