An organization that is implementing the ISMS based on ISO/IEC 27001 has defined and communicated secure system architecture and engineering principles. However, there is no documented information related to these principles. Is this acceptable?
I thought the standard was flexible about documentation, but now I'm questioning if that applies to secure system architecture principles specifically.
I feel like I came across a similar question in our practice exams, and it emphasized the need for documentation to support the principles communicated.
Elke
15 days agoFiliberto
20 days agoJanine
25 days agoAntonio
1 month agoFreida
1 month agoAvery
1 month agoJettie
2 months agoMarjory
2 months agoLuisa
2 months agoLeigha
2 months agoTanja
2 months agoLinn
2 months ago