Clause 9.3.2 Management review inputs
Clause 9.3.2 in ISO 27001:2022 (ISO/IEC 27001:2022). All ISO 27001:2022 controls held. Open ISO 27001:2022 on the standards site.
The control as we hold it
Management review inputs. Management review has to take into account: the status of actions from earlier reviews; changes in internal and external issues relevant to the ISMS; changes in what relevant interested parties need and expect; feedback on how information security is performing, including trends in nonconformities and corrective actions, in monitoring and measurement results, in audit results and in how far objectives are being met; feedback received from interested parties; what the risk assessment found and how far the risk treatment plan has progressed; and where continual improvement is possible.
Reviewed and closest counterparts in the other frameworks
We hold no cross-framework row for Clause 9.3.2 yet. The reviewed pairs page lists the released pairs and their coverage.
What an auditor commonly asks for
General guidance for this control area (domain: Clause 9), in our words, not a statement of the standard and not binding on an assessor.
- A management review agenda or input pack covering each required input
- Trend data on nonconformities, measurement, audits and objectives
- Status of previous review actions
- Risk assessment results and treatment plan status presented to the review