What is the purpose of management review in ISO/IEC 27001:2022?
A.
To ensure that the information security policy matches all identified risks
B.
To ensure that employees receive information about updates to information security policies
C.
To ensure the continuing suitability, adequacy, and effectiveness of the ISMS
D.
To ensure that the information security policy covers all controls indicated in ISO/IEC 27001
The Answer Is:
C
This question includes an explanation.
Explanation:
ISO/IEC 27001:2022 requires top management to review the organization’s ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness. Management review is a formal requirement under performance evaluation and is intended to confirm that the ISMS continues to support the organization’s objectives and strategic direction. It is broader than policy review alone and is not limited to communication or Annex A coverage. Therefore, option C is correct.
=======
I27001F PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"