ISO 27001 5.1 Policies for Information Security Requirement:
"Information security policy and topic-specific policies shall be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur."[1]
ISO 27001 5.1 Policies for Information Security Requirement Explanation:
Information security policies define the organization's security objectives. The information security policy is supported by management granting legitimacy to the organization's security program.
References:
Quick & Simple
Discover Our Cybersecurity Compliance Solutions:
Whether you need to meet and maintain your compliance requirements, help your clients meet them, or verify supplier compliance we have the expertise and solution for you