Question group
Governance and policy
The opening section of almost every questionnaire: is there a policy, who owns security, is risk assessed, and has anyone independent looked. These questions draw on the documents a certificate already rests on.
The families
4 families| Family and a typical question | ISO 27001 | Evidence expected |
|---|---|---|
| Information security policyDo you maintain an information security policy approved by management? | 5.1 | The approved top-level security policy with its approval record and last review date, and the list of topic policies that sit under it. |
| Security roles and a named security leadWho is responsible for information security in your organisation? | 5.2 | An organisation chart or role description naming who owns information security, the reporting line, and the roles below it. |
| Risk assessmentDo you perform a formal information security risk assessment at least annually? | none | The risk assessment method, the current risk register with owners and treatment decisions, and the date of the last full assessment. |
| Independent audit and certificationIs your organisation independently audited against a recognised security standard? | 5.35 | The current certificate or attestation report with its scope statement and period, and the latest internal audit summary. |