The answer here is c
Yes, but documenting each security control and not the process in general will make it difficult to review the documented information
ISO/IEC 27001 does not specify the form of the SoA.
It requires, however that it includes a list of the information security controls, the justification for the inclusions, and actions taken to implement the selected controls.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Acrisius
2 months, 2 weeks ago