What I was wondering in a few occasions in general is Security Board/Council mandatory for certifications by ISO Standards or just best practice?
Answer:
If you mean with Security Board/Council a group of people to manage the ISMS (I have seen this name in some organizations: Security committee"), it was mandatory in the old version of the standard ISO 27001:2005, but in the current version ISO 27001:2013 it is just a best practice.
Finally, I think that can be useful for you to know the list of mandatory documents (and non mandatory) so please see this article List of mandatory documents required by ISO 27001 (2013 revision) : https://advisera.com/27001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-27001-2013-revision/
Comment as guest or Sign in
Jan 12, 2016
Jan 12, 2016
Jan 12, 2016