nerdexam
(ISC)2

CISSP · Question #194

Which of the following standards/guidelines requires an Information Security Management System (ISMS) to be defined?

The correct answer is A. International Organization for Standardization (ISO) 27000 family. The International Organization for Standardization (ISO) 27000 family of standards/guidelines requires an Information Security Management System (ISMS) to be defined. An ISMS is a systematic approach to managing the security of information assets, such as data, systems, processes

Submitted by brentm· Mar 5, 2026Security and Risk Management

Question

Which of the following standards/guidelines requires an Information Security Management System (ISMS) to be defined?

Options

  • AInternational Organization for Standardization (ISO) 27000 family
  • BInformation Technology Infrastructure Library (ITIL)
  • CPayment Card Industry Data Security Standard (PCIDSS)
  • DISO/IEC 20000

How the community answered

(46 responses)
  • A
    91% (42)
  • B
    4% (2)
  • C
    2% (1)
  • D
    2% (1)

Explanation

The International Organization for Standardization (ISO) 27000 family of standards/guidelines requires an Information Security Management System (ISMS) to be defined. An ISMS is a systematic approach to managing the security of information assets, such as data, systems, processes, and people. An ISMS includes policies, procedures, controls, and activities that aim to protect the confidentiality, integrity, and availability of information, as well as to comply with the legal and regulatory requirements. The ISO 27000 family provides best practices and guidance for establishing, implementing, maintaining, and improving an ISMS. The ISO 27001 standard specifies the requirements for an ISMS, while the other standards in the family provide more detailed or specific guidance on different aspects of information security

Topics

#ISMS#ISO 27001#Security standards

Community Discussion

No community discussion yet for this question.

Full CISSP Practice