Identify the missing word(s) in the following control relating to the Policies for information security control.
“Information security policy and topic-specific policies should be defined, approved by management, [ ? ] and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur.”
Which statement describes the Classification of information control in Annex A of ISO/IEC 27001?
To whom does the scope of the Terms and conditions of employment control apply?
Which action is a required response to an identified residual risk?
Which statement is a factor that will influence the implementation of the information security management system?