Publishing an annual report on information security performance is a tangible way to demonstrate ongoing commitment to continual improvement. This aligns with ISO/IEC 27001 requirements for continual improvement (Clause 10.2) and transparency regarding ISMS effectiveness.
“The organization shall continually improve the suitability, adequacy, and effectiveness of the information security management system.”
— ISO/IEC 27001:2022, Clause 10.2
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit