A financial services company is migrating its customer relationship management (CRM) system to a public cloud service. According to ISO 27001:2022 Annex A, which control specifically requires the company to establish and manage information security requirements for this transition and ongoing use?
-
A
A.5.1 Policy for information security
-
B
A.8.1 User endpoint devices
-
C
A.5.23 Information security for use of cloud services
-
D
A.5.19 Information security in supplier relationships