An auditor asks an organization to demonstrate compliance with ISO/IEC 27001:2022 Clause 10.1. Which ongoing outcome must the organization show it is pursuing?
- A.Eliminating all residual risk from every information asset
- B.Continually improving the suitability, adequacy and effectiveness of the ISMS
- C.Achieving zero security incidents during the certification cycle
- D.Reducing the number of Annex A controls applied each year
Why B is correct
Clause 10.1 requires the organization to continually improve the suitability, adequacy and effectiveness of the ISMS. It does not demand elimination of all risk or zero incidents, which are unrealistic absolutes.
Know someone studying for ISO 27001? Send them this one.