Implementation of ISO-27001
Assign topic to the user
According to ISO 27001, the ultimate actions and decisions to be considered for the ISMS are those from the top management, not those from the owner of the company - of course, if the owner of the company is also its CEO then this person will have full power to make decisions.
In practice, the top management will have to act and decide on how to support the ISMS with resources and ensure security policies and procedures are followed, if not, the company might lose its certificate.
In case the top management wants to change some security objectives/controls/priorities/resources, etc. this must be in writing, taking into account risks and requirements of interested parties (e.g., the company’s owner, customers, suppliers, government, etc.) - in other words, such decisions must be made taking into account the security needs.
Comment as guest or Sign in
Mar 04, 2022