CISSP · Question #194
Which of the following standards/guidelines requires an Information Security Management System (ISMS) to be defined?
The correct answer is A. International Organization for Standardization (ISO) 27000 family. The International Organization for Standardization (ISO) 27000 family of standards/guidelines requires an Information Security Management System (ISMS) to be defined. An ISMS is a systematic approach to managing the security of information assets, such as data, systems, processes
Question
Options
- AInternational Organization for Standardization (ISO) 27000 family
- BInformation Technology Infrastructure Library (ITIL)
- CPayment Card Industry Data Security Standard (PCIDSS)
- DISO/IEC 20000
How the community answered
(46 responses)- A91% (42)
- B4% (2)
- C2% (1)
- D2% (1)
Explanation
The International Organization for Standardization (ISO) 27000 family of standards/guidelines requires an Information Security Management System (ISMS) to be defined. An ISMS is a systematic approach to managing the security of information assets, such as data, systems, processes, and people. An ISMS includes policies, procedures, controls, and activities that aim to protect the confidentiality, integrity, and availability of information, as well as to comply with the legal and regulatory requirements. The ISO 27000 family provides best practices and guidance for establishing, implementing, maintaining, and improving an ISMS. The ISO 27001 standard specifies the requirements for an ISMS, while the other standards in the family provide more detailed or specific guidance on different aspects of information security
Topics
Community Discussion
No community discussion yet for this question.