CSSLP · Question #102
Which of the following ISO standards provides guidelines for accreditation of an organization that is concerned with certification and registration related to ISMS?
The correct answer is A. ISO 27006. ISO 27006 specifies the requirements for bodies providing audit and certification of Information Security Management Systems (ISMS) to ensure their competence and consistency.
Question
Which of the following ISO standards provides guidelines for accreditation of an organization that is concerned with certification and registration related to ISMS?
Options
- AISO 27006
- BISO 27005
- CISO 27003
- DISO 27004
How the community answered
(64 responses)- A88% (56)
- B3% (2)
- C2% (1)
- D8% (5)
Why each option
ISO 27006 specifies the requirements for bodies providing audit and certification of Information Security Management Systems (ISMS) to ensure their competence and consistency.
ISO/IEC 27006 provides guidelines and requirements specifically for accreditation bodies that audit and certify organizations' Information Security Management Systems (ISMS) against the ISO 27001 standard. This ensures the integrity and reliability of the certification process itself.
ISO 27005 provides guidelines for information security risk management within an organization.
ISO 27003 offers guidance on the implementation and deployment of an ISMS based on ISO 27001.
ISO 27004 provides guidelines and metrics for evaluating the performance of an ISMS.
Concept tested: ISO 27000 series standards - ISMS certification
Topics
Community Discussion
No community discussion yet for this question.