ISO-IEC-27001-LEAD-AUDITOR · Question #67
Which two of the following statements are true?
The correct answer is A. The benefits of implementing an ISMS primarily result from a reduction in information security C. The purpose of an ISMS is to apply a risk management process for preserving information. The benefits of implementing an ISMS are not limited to a reduction in information security risks, but also include improved business performance, customer satisfaction, legal compliance, and stakeholder confidence. The benefit of certifying an ISMS is not only to obtain…
Question
Which two of the following statements are true?
Options
- AThe benefits of implementing an ISMS primarily result from a reduction in information security
- BThe benefit of certifying an ISMS is to obtain contracts from governmental institutions
- CThe purpose of an ISMS is to apply a risk management process for preserving information
- DThe purpose of an ISMS is to demonstrate compliance with regulatory requirements
How the community answered
(28 responses)- A86% (24)
- B11% (3)
- D4% (1)
Explanation
The benefits of implementing an ISMS are not limited to a reduction in information security risks, but also include improved business performance, customer satisfaction, legal compliance, and stakeholder confidence. The benefit of certifying an ISMS is not only to obtain contracts from governmental institutions, but also to demonstrate the organisation's commitment to information security to other potential customers, partners, and regulators. The purpose of an ISMS is to apply a risk management process for preserving information security, which means identifying, analysing, evaluating, treating, monitoring, and reviewing the information security risks that the organisation faces. The purpose of an ISMS is not to demonstrate compliance with regulatory requirements, but rather to ensure that the organisation meets its own information security objectives and obligations.
Topics
Community Discussion
No community discussion yet for this question.