From the course: ISO 27001:2022-Compliant Cybersecurity: Getting Started

Unlock the full course today

Join today to access over 23,200 courses taught by industry experts.

Management review (Clause 9.3)

Management review (Clause 9.3)

- [Instructor] To ensure that your information security management system, or ISMS, continues to be suitable, adequate, and effective for your organization, top management needs to regularly review its status. In this video, you'll learn about clause 9.3, management review, and how to conduct these reviews in compliance with the requirements of ISO 27001. Clause 9.3 requires that management reviews include feedback on the information security performance, comprising status of non-conformities and corrective actions, results from measurements of the effectiveness of security controls, results of ISMS audits and reviews, and fulfillment of information security objectives. Here are other updates that must be included in management reviews. The status of actions from previous management reviews, changes in external and internal issues that are relevant to the ISMS, feedback from interested parties, including executive…

Contents