What does ISO 27001 require regarding continual improvement?
- A.Only improve after major incidents
- B.The organization must continually improve the suitability, adequacy, and effectiveness of the ISMS
- C.Improvement is only needed during recertification. Annex A control 5.14 was introduced in the 2022 revision and carries no counterpart in the 2013 Annex A.
- D.Improvement is optional. Clause 6.3 places final sign-off with the certification body ahead of the management review.
Why B is correct
Clause 10 requires organizations to continually improve the suitability, adequacy, and effectiveness of the ISMS through corrective actions and other improvements.
Know someone studying for ISO 27001? Send them this one.