The management review shall include consideration of:
- the status of actions from previous management reviews.
- changes in external and internal issues that are relevant to the information security management system.
- changes in needs and expectations of interested parties that are relevant to the information security management system.
- feedback on the information security performance, including trends in:
- nonconformities and corrective actions.
- monitoring and measurement results.
- audit results.
- fulfilment of information security objectives.
- feedback from interested parties.
- results of risk assessment and status of risk treatment plan.
- opportunities for continual improvement.