Which item is required to be included in an information security policy?
Clause 5.2 (Information security policy) requires that the policy:
''includes information security objectives (or provides a framework for setting them)''
''includes a commitment to satisfy applicable requirements related to information security''
''includes a commitment to continual improvement of the ISMS.''
Among the listed options, the exact mandatory requirement is ''a commitment to satisfy applicable requirements related to information security''. Option B partially reflects Clause 5.2 (commitment to continual improvement), but the wording given in the standard prioritizes the satisfaction of applicable requirements (e.g., legal, regulatory, contractual). Option C is not a policy requirement. Option D (Statement of Applicability) is a separate mandatory document (Clause 6.1.3) and not part of the policy itself.
Thus, the correct answer is A.
Stanton
4 months agoJoseph
4 months agoMignon
4 months agoShawna
5 months agoMadalyn
5 months agoAliza
5 months agoBritt
5 months agoLeigha
5 months agoSamira
6 months agoJesusita
6 months agoTambra
6 months agoFallon
6 months agoKarima
6 months agoDaron
6 months agoGertude
7 months agoGlen
7 months agoLashon
8 months agoSunshine
8 months agoLili
8 months agoMarkus
8 months agoKirk
8 months agoChaya
9 months agoRosendo
9 months agoMee
3 months agoScot
4 months agoJanessa
7 months agoIsaiah
7 months agoMitzie
7 months ago