ISO 27001 Annex : A.5 Information Security Policies
5. 1 Management direction for information security ISO 27001 Annex : A.5 Information Security Policies, Its objective is to provide management guidance and information security assistance in accordance with business requirements and relevant laws and regulations. 5.1.1 Policies for Information Security Control- A set of information security policies should be established, managed accepted, published and communicated to the employees and related external parties. Implementation Guidance- At the very least companies need to identify a management-approved “information security strategy,” which outlines the organization’s approach to managing its information security goals. Information security policies should meet criteria that have been created by: Business strategy; Regulations, legislation and contracts; The present and projected information security threat environment Related Product : ISO 27001 Lead...
Comments
Post a Comment