nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #67

Which two of the following statements are true?

The correct answer is A. The benefits of implementing an ISMS primarily result from a reduction in information security C. The purpose of an ISMS is to apply a risk management process for preserving information. The benefits of implementing an ISMS are not limited to a reduction in information security risks, but also include improved business performance, customer satisfaction, legal compliance, and stakeholder confidence. The benefit of certifying an ISMS is not only to obtain…

ISMS Concepts and Principles

Question

Which two of the following statements are true?

Options

  • AThe benefits of implementing an ISMS primarily result from a reduction in information security
  • BThe benefit of certifying an ISMS is to obtain contracts from governmental institutions
  • CThe purpose of an ISMS is to apply a risk management process for preserving information
  • DThe purpose of an ISMS is to demonstrate compliance with regulatory requirements

How the community answered

(28 responses)
  • A
    86% (24)
  • B
    11% (3)
  • D
    4% (1)

Explanation

The benefits of implementing an ISMS are not limited to a reduction in information security risks, but also include improved business performance, customer satisfaction, legal compliance, and stakeholder confidence. The benefit of certifying an ISMS is not only to obtain contracts from governmental institutions, but also to demonstrate the organisation's commitment to information security to other potential customers, partners, and regulators. The purpose of an ISMS is to apply a risk management process for preserving information security, which means identifying, analysing, evaluating, treating, monitoring, and reviewing the information security risks that the organisation faces. The purpose of an ISMS is not to demonstrate compliance with regulatory requirements, but rather to ensure that the organisation meets its own information security objectives and obligations.

Topics

#ISMS purpose#risk management process#information security benefits#certification rationale

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice