ISO/IEC 27000 Policies for Information Security, v2022
Specifies requirements in accordance with the security and privacy controls specified by ISO/IEC Publication 27001:2022, related to policies for information security.
Assessment Step
1
Policies for Information Security (PoliciesforInformationSecurity)
Does the organization define, approve, publish, communicate, and periodically review its information security and topic-specific policies, and ensure they are acknowledged by relevant personnel and interested parties?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Policies for Information Security
Information security policy and topic-specific policies shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur.
Citations
27001
Annex A, Control 5.1
27002
Section 5.1
|