Which item is required to be included in an information security policy?
Clause 5.2 (Information security policy) requires that the policy:
''includes information security objectives (or provides a framework for setting them)''
''includes a commitment to satisfy applicable requirements related to information security''
''includes a commitment to continual improvement of the ISMS.''
Among the listed options, the exact mandatory requirement is ''a commitment to satisfy applicable requirements related to information security''. Option B partially reflects Clause 5.2 (commitment to continual improvement), but the wording given in the standard prioritizes the satisfaction of applicable requirements (e.g., legal, regulatory, contractual). Option C is not a policy requirement. Option D (Statement of Applicability) is a separate mandatory document (Clause 6.1.3) and not part of the policy itself.
Thus, the correct answer is A.
Stanton
5 months agoJoseph
5 months agoMignon
6 months agoShawna
6 months agoMadalyn
6 months agoAliza
7 months agoBritt
7 months agoLeigha
7 months agoSamira
7 months agoJesusita
7 months agoTambra
7 months agoFallon
8 months agoKarima
8 months agoDaron
8 months agoGertude
8 months agoGlen
9 months agoLashon
9 months agoSunshine
9 months agoLili
10 months agoMarkus
10 months agoKirk
10 months agoChaya
10 months agoRosendo
10 months agoMee
5 months agoScot
5 months agoJanessa
8 months agoIsaiah
9 months agoMitzie
9 months ago