Which item is required to be included in an information security policy?
Clause 5.2 (Information security policy) requires that the policy:
''includes information security objectives (or provides a framework for setting them)''
''includes a commitment to satisfy applicable requirements related to information security''
''includes a commitment to continual improvement of the ISMS.''
Among the listed options, the exact mandatory requirement is ''a commitment to satisfy applicable requirements related to information security''. Option B partially reflects Clause 5.2 (commitment to continual improvement), but the wording given in the standard prioritizes the satisfaction of applicable requirements (e.g., legal, regulatory, contractual). Option C is not a policy requirement. Option D (Statement of Applicability) is a separate mandatory document (Clause 6.1.3) and not part of the policy itself.
Thus, the correct answer is A.
Stanton
2 months agoJoseph
2 months agoMignon
3 months agoShawna
3 months agoMadalyn
3 months agoAliza
4 months agoBritt
4 months agoLeigha
4 months agoSamira
4 months agoJesusita
4 months agoTambra
4 months agoFallon
5 months agoKarima
5 months agoDaron
5 months agoGertude
5 months agoGlen
6 months agoLashon
6 months agoSunshine
6 months agoLili
7 months agoMarkus
7 months agoKirk
7 months agoChaya
7 months agoRosendo
7 months agoMee
2 months agoScot
2 months agoJanessa
5 months agoIsaiah
6 months agoMitzie
6 months ago