Question
The top management of a company has designated specific personnel within the company to be responsible for reporting on the performance of the ISMS. These individuals are tasked with gathering relevant ISMS data, preparing reports, and ensuring that necessary information reaches the top management.
Does this approach align with ISO/IEC 27001 requirements?
Question
Company XYZ, a software development company certified under ISO/IEC 27001, informs the certification body a year after certification that they are not prepared for the scheduled surveillance audit and refuse to undergo it. What is the immediate consequence in this situation?
Finnco, a subsidiary of a certification body, provided ISMS consultancy services to an organization. Considering this scenario, when can the certification body certify the organization?
Question:
Which controls are related to the Annex A controls of ISO/IEC 27001 and are often selected from other guides and standards or defined by the organization to meet its specific needs?