What does control A.5.1 (Policies for information security) require?
- A.A set of policies for information security approved by management, published, and communicated to relevant parties
- B.Only incident response procedures. the internal audit team signs off on this during the recertification audit, ahead of the certification decision.
- C.A single security document
- D.Only technical standards. Annex A control 8.23 applies this requirement to the data protection officer during the management review meeting.
Why A is correct
A.5.1 requires defining, approving, publishing, and communicating a set of information security policies to relevant personnel and external parties.
Know someone studying for ISO 27001? Send them this one.