nerdexam
EC-Council

712-50 · Question #51

An organization is looking for a framework to measure the efficiency and effectiveness of their Information Security Management System. Which of the following international standards can BEST assist…

The correct answer is A. International Organization for Standardizations ?27004 (ISO-27004). ISO 27004 is specifically designed to provide guidelines for monitoring, measurement, analysis, and evaluation of an Information Security Management System (ISMS), making it the ideal standard for assessing ISMS efficiency and effectiveness. PCI-DSS (B) is a payment card…

IS Management Controls and Auditing Management

Question

An organization is looking for a framework to measure the efficiency and effectiveness of their Information Security Management System. Which of the following international standards can BEST assist this organization?

Options

  • AInternational Organization for Standardizations ?27004 (ISO-27004)
  • BPayment Card Industry Data Security Standards (PCI-DSS)
  • CControl Objectives for Information Technology (COBIT)
  • DInternational Organization for Standardizations ?27005 (ISO-27005)

How the community answered

(29 responses)
  • A
    86% (25)
  • B
    7% (2)
  • C
    3% (1)
  • D
    3% (1)

Explanation

ISO 27004 is specifically designed to provide guidelines for monitoring, measurement, analysis, and evaluation of an Information Security Management System (ISMS), making it the ideal standard for assessing ISMS efficiency and effectiveness. PCI-DSS (B) is a payment card industry compliance standard focused on protecting cardholder data, not a general ISMS measurement framework. COBIT (C) is an IT governance framework broader than information security measurement, addressing overall IT management and enterprise goals. ISO 27005 (D) covers information security risk management - identifying and treating risks - not measuring how well the ISMS itself performs.

Memory tip: Think of ISO 27004 as "4 measuring" - the "4" helps you remember it's the standard for measuring your ISMS performance, while ISO 27005 is for risk (risk = "5-letter word").

Topics

#ISMS measurement#ISO-27004#Security metrics#Compliance frameworks

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice