CCSP · Question #349
An audit against the __________ will demonstrate that an organization has a holistic, comprehensive security program. Response:
The correct answer is D. ISO 27001 certification requirements. ISO 27001 certification specifically assesses an organization's Information Security Management System (ISMS), demonstrating a holistic and comprehensive approach to information security.
Question
An audit against the __________ will demonstrate that an organization has a holistic, comprehensive security program. Response:
Options
- ASAS 70 standard
- BSSAE 16 standard
- CSOC 2, Type 2 report matrix
- DISO 27001 certification requirements
How the community answered
(50 responses)- A2% (1)
- B2% (1)
- C4% (2)
- D92% (46)
Why each option
ISO 27001 certification specifically assesses an organization's Information Security Management System (ISMS), demonstrating a holistic and comprehensive approach to information security.
SAS 70 was an auditing standard focused on internal controls at service organizations, primarily for financial reporting, and has been superseded.
SSAE 16 superseded SAS 70 and is primarily focused on financial reporting controls at service organizations, not a holistic security program.
A SOC 2, Type 2 report evaluates a service organization's controls related to security, availability, processing integrity, confidentiality, or privacy over a period, but it is a report on controls, not a certification for a holistic security program itself.
ISO 27001 is an internationally recognized standard for information security management systems (ISMS), requiring an organization to implement a comprehensive framework for managing information security risks. Achieving ISO 27001 certification validates that an organization has established, implemented, maintained, and continually improved a documented ISMS across all relevant areas.
Concept tested: Information Security Management Systems (ISMS) Standards
Source: https://www.iso.org/iso-27001-information-security.html
Topics
Community Discussion
No community discussion yet for this question.