Security Policy: Difference between revisions
Jump to navigation
Jump to search
m →General |
|||
| Line 202: | Line 202: | ||
The organization’s information security management system shall include: | The organization’s information security management system shall include: | ||
:1. | :1. documented information required by this International Standard; and | ||
:2. | :2. documented information determined by the organization as being necessary for the effectiveness of the information security management system. | ||
<small>NOTE The extent of documented information for an information security management system can differ from one organization to another due to: </small> | <small>NOTE The extent of documented information for an information security management system can differ from one organization to another due to: </small> | ||
:3. | :3. the size of organization and its type of activities, processes, products and services; | ||
:4. | :4. the complexity of processes and their interactions; and | ||
:5. | :5. the competence of persons. | ||
====Creating and updating==== | ====Creating and updating==== | ||