An organization has completed its risk assessment and developed a comprehensive risk treatment plan. According to ISO/IEC 27001 Clause 8 (Operation), what is the key activity the organization must now undertake?
-
A
Conduct a management review of the risk treatment plan.
-
B
Implement the information security risk treatment plan.
-
C
Redefine the scope of the Information Security Management System (ISMS).
-
D
Perform a new risk assessment based on the treatment plan.