Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CertiProf I27001F Exam - Topic 1 Question 12 Discussion

What is the purpose of management review in ISO/IEC 27001:2022?
C) To ensure the continuing suitability, adequacy, and effectiveness of the ISMS
A) To ensure that the information security policy matches all identified risks
B) To ensure that employees receive information about updates to information security policies
D) To ensure that the information security policy covers all controls indicated in ISO/IEC 27001

CertiProf I27001F Exam - Topic 1 Question 12 Discussion

Actual exam question for CertiProf's I27001F exam
Question #: 12
Topic #: 1
[All I27001F Questions]

What is the purpose of management review in ISO/IEC 27001:2022?

Show Suggested Answer Hide Answer
Suggested Answer: C

ISO/IEC 27001:2022 requires top management to review the organization's ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness. Management review is a formal requirement under performance evaluation and is intended to confirm that the ISMS continues to support the organization's objectives and strategic direction. It is broader than policy review alone and is not limited to communication or Annex A coverage. Therefore, option C is correct.

=======


Contribute your Thoughts:

0/2000 characters
Caprice
16 hours ago
True, but D ensures all controls are covered.
upvoted 0 times
...
Asuncion
6 days ago
But C covers effectiveness too. That's crucial.
upvoted 0 times
...
Raylene
11 days ago
I prefer B. Employees should be informed.
upvoted 0 times
...
Glen
16 days ago
A is also valid. Risks need to match policies.
upvoted 0 times
...
Kirk
21 days ago
Agreed, C makes sense. Suitability is key.
upvoted 0 times
...
Denny
26 days ago
I think it's C. Very important for ISMS.
upvoted 0 times
...
Sue
1 month ago
Not sure if D is really a priority during reviews.
upvoted 0 times
...
Kiera
1 month ago
B is crucial too, can't leave employees in the dark.
upvoted 0 times
...
Julie
1 month ago
Surprised that some people overlook the importance of C!
upvoted 0 times
...
Hildegarde
2 months ago
I think A is just as important!
upvoted 0 times
...
Emmanuel
2 months ago
C is definitely the main goal of the management review.
upvoted 0 times
...
Avery
2 months ago
I thought it was about matching the policy with risks, but now I'm questioning if that's really the main goal of the management review.
upvoted 0 times
...
Lillian
2 months ago
I feel like the review also touches on policies and controls, but I can't recall if that's the primary purpose.
upvoted 0 times
...
Cassandra
2 months ago
I remember a practice question that emphasized the importance of ongoing suitability and effectiveness, which makes me lean towards option C.
upvoted 0 times
...
Linn
2 months ago
I think the management review is mainly about ensuring the ISMS is effective, but I'm not entirely sure if that's the only focus.
upvoted 0 times
...

Save Cancel