An organization that is implementing the ISMS based on ISO/IEC 27001 has defined and communicated secure system architecture and engineering principles. However, there is no documented information related to these principles. Is this acceptable?
I thought the standard was flexible about documentation, but now I'm questioning if that applies to secure system architecture principles specifically.
I feel like I came across a similar question in our practice exams, and it emphasized the need for documentation to support the principles communicated.
Jettie
24 hours agoMarjory
6 days agoLuisa
11 days agoLeigha
16 days agoTanja
22 days agoLinn
27 days ago