Information Security Objectives and management support
Assign topic to the user
Cesar,
Clause 5.2 of ISO 27001 requires you to include the things you mentioned in the top-level Information Security Policy:
- the management commitment to information security, and
- specify the information security objectives, or provide a framework for setting objectives (in this case, the objectives are documented separately)
Comment as guest or Sign in
Jan 12, 2016

