“Top management shall review the organization’s ISMS, at planned intervals, to ensure its continuing suitability, adequacy and effectiveness.”
While the ultimate responsibility rests with top management, reviews may be conducted at multiple organizational levels for broader visibility and alignment. ISO/IEC 27004 also supports reviews at tactical and operational levels.
There is no requirement for monthly reviews. Option C is incorrect, as top management cannot fully delegate the ultimate responsibility, only supporting roles.