QuestionQ109

Information Security Management

A multinational organization operating in a regulated environment has developed information security management policies and communicated them to staff.

What is the BEST approach for deciding when these policies should be reviewed?

  • A The policies should be reviewed as often as required by the regulations and whenever the regulations change
  • B The policies should be reviewed at least once a month, addressing any recent regulatory changes
  • C The policies should be reviewed regularly and following significant events, including changes in regulations
  • D The policies should be reviewed upon requests from the business stakeholders
Explanation

Information-security policies should be reviewed at planned, regular intervals and whenever significant changes occur, so they remain suitable, adequate, and effective. Regulatory changes are one important significant event, but review triggers should also cover other material organizational, risk, and operational changes.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!