Which action must top management take to provide evidence of its commitment to the establishment, operation and improvement of the ISMS?
Which attribute is NOT a required focus of continual ISMS improvement?
Identify the missing word in the following sentence.
According to ISO/IEC 27000, the definition of risk [?] is a “process to comprehend the nature of risk and to determine the level of risk.”
Which activity is a required element of information security risk identification?