According to ISO/IEC 27001, which three elements must an organization consider when determining the boundaries and applicability of its Information Security Management System (ISMS)?
-
A
Risk assessment results, business continuity plans, and physical security perimeters.
-
B
The organization's asset inventory, the IT department's structure, and the annual security budget.
-
C
External and internal issues, requirements of interested parties, and interfaces and dependencies with other organizations.
-
D
The number of employees, the geographical locations of offices, and the primary products or services offered.