|
Management Review This part of the IMS deals with management review of the IMS. The reviews are at least annually and are held by the IMSF. Their purpose is for the IMSF to take stock and set direction. The review meetings have no constraints. They are intended to challenge the scope of the IMS, its policies and the risk assessment as well as whether its requirements are being met. Thus, the purpose of the review is as much about review current, and future, need for information security and quality as it is about the effectiveness of controls, as actually practiced, to meet the currently stated objectives.
|
||