An organization holds a single management review only when its certification audit approaches, roughly every three years. Why is this likely insufficient?
- A.The standard prescribes monthly reviews
- B.Reviews are only needed after a major incident
- C.Top management is not required to be involved, so frequency is irrelevant
- D.Reviews must occur at planned intervals appropriate to keep the ISMS suitable, adequate and effective, and a three-year gap rarely supports timely decisions
Why D is correct
Clause 9.3.1 requires top management to review the ISMS at planned intervals to ensure its continuing suitability, adequacy and effectiveness. Reviewing only at recertification provides too little oversight for a system that should respond to changing risks.
Know someone studying for ISO 27001? Send them this one.