Which approach should organizations use to implement an ISMS based on ISO/IEC 27001?
Which approach should organizations use to implement an ISMS based on ISO/IEC 27001?
Answer A is correct : as this an organisations ISMS needs to be implemented within the organisations scope as the organisation my for example want ISMS to cover only departments that handle customer data. ....There is not time limit to how long it should take to implement an ISMS so answer B is wrong.