An organization has completed its first full PDCA cycle for its ISMS. What should it do next?
-
A
Disband the ISMS team since implementation is complete
-
B
Archive all documents and start fresh with a new framework
-
C
Begin a new PDCA cycle incorporating lessons learned from the first cycle
-
D
Wait for the next security incident before reviewing