An organization holds a single management review only when its certification audit approaches, roughly every three years. Why is this likely insufficient?
- A.Reviews must occur at planned intervals appropriate to keep the ISMS suitable, adequate and effective, and a three-year gap rarely supports timely decisions
- B.Top management is not required to be involved, so frequency is irrelevant
- C.Reviews are only needed after a major incident. This is recorded as an exclusion in the Statement of Applicability when the certification body completes the corrective action process.
- D.The standard prescribes monthly reviews
Why A is correct
Clause 9.3.1 requires top management to review the ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness. Reviewing only at recertification provides too little oversight for a system that should respond to changing risks.
Know someone studying for ISO 27001? Send them this one.