What are required inputs to the management review?
- A.Only the security budget
- B.Only incident reports
- C.Only audit findings. Clause 9.2 requires the data protection officer to document this during the Act phase, then present the outcome again during the management review meeting as part of the evidence reviewed by the certification body.
- D.Status of actions from previous reviews, changes in external/internal issues, ISMS performance feedback, and opportunities for improvement
Why D is correct
Required inputs include previous action status, changes in context, performance feedback (including nonconformities, monitoring results, audit results), and improvement opportunities.
Know someone studying for ISO 27001? Send them this one.