Clause 5.1 (Leadership and Commitment) requires top management to demonstrate leadership by:
“ensuring the information security policy and the information security objectives are established and are compatible with the strategic direction of the organization;”
“ensuring the integration of the ISMS requirements into the organization’s processes;”
“ensuring that the resources needed for the ISMS are available;”
Among the options, the one explicitly mandated isensuring that information security objectives are established. Risk assessments (C) and implementing audit actions (D) are responsibilities of management but not the direct leadership evidence required in Clause 5.1. Communicating interested party feedback (A) is relevant but not specifically cited as leadership evidence. Thus, the verified answer isB.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit