A multinational company defines its ISMS scope to cover only its US operations. Which obligation must it still consider?
-
A
It has no further obligations since the scope is limited
-
B
Interfaces with out-of-scope regions that could affect information security
-
C
Implementing ISO 27001 in all regions immediately
-
D
Hiring separate security staff for each region