A.5.1.1 Policies for Information Security
Assign topic to the user
Please note that ‘Setting top-level information security objectives and intentions’ is related to the Information Security Policy, which is a mandatory document for ISO 27001, so it needs to be implemented regardless of whether the controls from sections A.5 and A.7 are applicable or not, so then they are not linked to these controls.
Comment as guest or Sign in
Jul 19, 2022

