The information security policy must be known by:
ISO/IEC 27001:2022 requires the information security policy to be available as documented information, communicated within the organization, and available to interested parties as appropriate. In practical terms, this means the policy must be communicated to relevant persons in the organization so they understand the direction and expectations related to information security. Among the options provided, the best and correct answer is D, because the policy is intended to be known broadly across the organization, not restricted to a single role or department.
Isadora
2 days agoChuck
7 days agoToshia
12 days agoHarley
18 days agoTatum
23 days agoSharika
28 days agoJenifer
3 months agoDaniela
3 months agoRashida
3 months agoAlex
4 months agoRosalind
4 months agoEliseo
4 months ago