Which item is required to be included in an information security policy?
Clause 5.2 (Information security policy) requires that the policy:
''includes information security objectives (or provides a framework for setting them)''
''includes a commitment to satisfy applicable requirements related to information security''
''includes a commitment to continual improvement of the ISMS.''
Among the listed options, the exact mandatory requirement is ''a commitment to satisfy applicable requirements related to information security''. Option B partially reflects Clause 5.2 (commitment to continual improvement), but the wording given in the standard prioritizes the satisfaction of applicable requirements (e.g., legal, regulatory, contractual). Option C is not a policy requirement. Option D (Statement of Applicability) is a separate mandatory document (Clause 6.1.3) and not part of the policy itself.
Thus, the correct answer is A.
Shawna
3 days agoMadalyn
9 days agoAliza
14 days agoBritt
19 days agoLeigha
24 days agoSamira
29 days agoJesusita
1 month agoTambra
1 month agoFallon
1 month agoKarima
2 months agoDaron
2 months agoGertude
2 months agoGlen
3 months agoLashon
3 months agoSunshine
3 months agoLili
3 months agoMarkus
4 months agoKirk
4 months agoChaya
4 months agoRosendo
4 months agoJanessa
2 months agoIsaiah
2 months agoMitzie
3 months ago