Exam ISO-IEC-27001-Lead-Implementer Topic 5 Question 117 Discussion
Actual exam question for PECB's ISO-IEC-27001-Lead-Implementer exam
Question #: 117
Topic #: 5
Question #: 117
Topic #: 5
Which option below should be addressed in an information security policy?
Suggested Answer: B Vote an answer
According to the ISO/IEC 27001:2022 standard, an information security policy is a high-level document that defines the management approach and objectives for information security within the organization. It should include, among other things, the legal and regulatory obligations imposed upon the organization, such as compliance with laws, contracts, agreements, and standards that are relevant to information security. The information security policy should also provide the basis for establishing, implementing, maintaining, and continually improving the information security management system (ISMS).
by Dora at Apr 15, 2025, 04:58 PM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).