Management review policy
Assign topic to the user
Answer:
ISO 27001 does not require a specific management review policy to be documented. The requirement for top management to review the ISMS can be found on the Information Security Policy, section 4.5. This template can be found on folder 04 Information Security Policy.
It is important to note that in large majority of cases smaller companies do not write separate Management Review Policy, this is why we didn’t include it into the toolkit.
This article will provide you further explanation about mandatory documents for ISO 27001:
- List of mandatory documents required by ISO 27001 (2013 revision) https://advisera.com/27001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-27001-2013-revision/
Comment as guest or Sign in
Mar 21, 2019