ISO/IEC 27000 Independent Review of Information Security, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to independent review of information security.
Assessment Step
1
Independent Review of Information Security (IndependentReviewofInformationSecurity)
Is the organization's approach to managing information security and its implementation - including people, processes, and technologies - reviewed independently at planned intervals or when significant changes occur?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Independent Review of Information Security
The organization's approach to managing information security and its implementation including people, processes and technologies shall be reviewed independently at planned intervals, or when significant changes occur.
Citations
27001
Annex A, Control 5.35
27002
Section 5.35
|