Information security management policy vs information security policy
Assign topic to the user
Answer:
Yes, in the context of ISO 27001 this is the same document - such a document defines top-level management intent regarding information security and general roles and responsibilities.
Detailed security rules are usually written through detailed policies, for example in our toolkit you will see IT Security Policy that describes detailed general rules for all employees.
Comment as guest or Sign in
Sep 04, 2018

