To whom are the information security policies required to be communicated, according to the control in Annex A of ISO/IEC 27001?
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
Annex A.5.1 (Policies for information security) clearly specifies:
''Information security policy and topic-specific policies should be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties...''
This means the communication obligation is not limited to top management (A) or only ISMS staff (B), nor does it stop at employees only (C). Instead, ISO/IEC 27001/27002 mandate a broader scope: all relevant personnel and relevant interested parties must be informed. This ensures both internal stakeholders (employees, contractors, temporary staff) and external interested parties (suppliers, partners, regulators, customers, etc.) receive the right policy communications where applicable. Therefore, the correct and verified answer is D.
Timothy
6 days agoLatrice
11 days agoTyra
16 days agoSkye
21 days agoLynna
26 days agoRutha
1 month agoDan
1 month agoTanja
1 month agoCherry
2 months agoCarey
2 months agoValentin
2 months agoDan
2 months ago