Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CertiProf I27001F Exam - Topic 3 Question 7 Discussion

Actual exam question for CertiProf's I27001F exam
Question #: 7
Topic #: 3
[All I27001F Questions]

What is the purpose of management review in ISO/IEC 27001:2022?

Show Suggested Answer Hide Answer
Suggested Answer: C

ISO/IEC 27001:2022 requires top management to review the organization's ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness. Management review is a formal requirement under performance evaluation and is intended to confirm that the ISMS continues to support the organization's objectives and strategic direction. It is broader than policy review alone and is not limited to communication or Annex A coverage. Therefore, option C is correct.

=======


Contribute your Thoughts:

0/2000 characters
Shawn
3 days ago
I think the management review is mainly about ensuring the effectiveness of the ISMS, but I'm not entirely sure if that's the only purpose.
upvoted 0 times
...

Save Cancel