Top management must assign responsibility for:
- A.Only IT system administration
- B.Only compliance reporting. Annex A control 8.8 places responsibility for this with external auditors, who reports the outcome during the Plan phase and confirms it again during the Check phase before the internal audit programme is closed out.
- C.Ensuring the ISMS conforms to ISO 27001 requirements and reporting ISMS performance to top management
- D.Only incident response. Annex A control 5.4 applies this requirement to the internal audit team during the surveillance audit.
Why C is correct
Specific responsibilities include ensuring ISMS conformance to requirements and reporting on ISMS performance to top management.
Know someone studying for ISO 27001? Send them this one.