Identify the missing word(s) in the following control relating to the Policies for information security
control.
œInformation security policy and topic-specific policies should be defined, approved by management,
[ ? ] and acknowledged by relevant personnel and relevant interested parties, and reviewed at
planned intervals and if significant changes occur.