Which item is required to be included in an information security policy?
Clause 5.2 (Information security policy) requires that the policy:
''includes information security objectives (or provides a framework for setting them)''
''includes a commitment to satisfy applicable requirements related to information security''
''includes a commitment to continual improvement of the ISMS.''
Among the listed options, the exact mandatory requirement is ''a commitment to satisfy applicable requirements related to information security''. Option B partially reflects Clause 5.2 (commitment to continual improvement), but the wording given in the standard prioritizes the satisfaction of applicable requirements (e.g., legal, regulatory, contractual). Option C is not a policy requirement. Option D (Statement of Applicability) is a separate mandatory document (Clause 6.1.3) and not part of the policy itself.
Thus, the correct answer is A.
Stanton
24 days agoJoseph
29 days agoMignon
1 month agoShawna
2 months agoMadalyn
2 months agoAliza
2 months agoBritt
2 months agoLeigha
2 months agoSamira
3 months agoJesusita
3 months agoTambra
3 months agoFallon
3 months agoKarima
3 months agoDaron
3 months agoGertude
4 months agoGlen
4 months agoLashon
5 months agoSunshine
5 months agoLili
5 months agoMarkus
5 months agoKirk
5 months agoChaya
6 months agoRosendo
6 months agoMee
13 days agoScot
18 days agoJanessa
4 months agoIsaiah
4 months agoMitzie
4 months ago