nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #94

Which two of the following statements are true?

The correct answer is D. The benefits of implementing an ISMS primarily result from a reduction in information security E. The purpose of an ISMS is to apply a risk management process for preserving information. The benefits of implementing an ISMS primarily result from a reduction in information security security. Comprehensive and Detailed According to the ISO 27001 standard, the benefits of implementing an ISMS include the following1: Assuring customers and other stakeholders of the…

Information Security Management System Overview

Question

Which two of the following statements are true?

Options

  • AThe benefit of certifying an ISMS is to show the accreditation certificate on the website.
  • BThe purpose of an ISMS is to demonstrate awareness of information security issues by
  • CThe benefit of certifying an ISMS is to increase the number of customers.
  • DThe benefits of implementing an ISMS primarily result from a reduction in information security
  • EThe purpose of an ISMS is to apply a risk management process for preserving information
  • FThe purpose of an ISMS is to demonstrate compliance with regulatory requirements.

How the community answered

(22 responses)
  • B
    5% (1)
  • D
    86% (19)
  • F
    9% (2)

Explanation

The benefits of implementing an ISMS primarily result from a reduction in information security security. Comprehensive and Detailed According to the ISO 27001 standard, the benefits of implementing an ISMS include the following1: Assuring customers and other stakeholders of the confidentiality, integrity and availability of Enhancing the ability to respond to information security incidents and minimize their impacts Improving the governance and management of information security Reducing the costs and losses associated with information security breaches Increasing the competitiveness and reputation of the organization Complying with legal, regulatory and contractual obligations. The purpose of an ISMS is to provide a systematic approach to managing information security risks, based on the Plan-Do- Check-Act (PDCA) cycle1. The ISMS enables the organization to establish, implement, maintain and continually improve its information security performance, in alignment with its business objectives and the needs and expectations of interested parties1. The ISMS consists of the following elements1: The information security policy and objectives The scope and boundaries of the ISMS The processes and procedures for information security risk assessment and treatment The resources and competencies for information security The roles and responsibilities for information security The performance evaluation and improvement of the ISMS The internal and external communication and awareness of the ISMS

Topics

#ISMS purpose#ISMS benefits#risk management#information security objectives

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice