nerdexam
PECB

LEAD-AUDITOR · Question #9

What is the standard definition of ISMS?

The correct answer is D. A systematic approach for establishing, implementing, operating, monitoring, reviewing,. The standard definition of ISMS is a systematic approach for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security to achieve business objectives. This definition is given in clause 3.17 of ISO/IEC 27001:202

ISMS Fundamentals

Question

What is the standard definition of ISMS?

Options

  • AIs an information security systematic approach to achieve business objectives for implementation,
  • BA company wide business objectives to achieve information security awareness for establishing,
  • CA project-based approach to achieve business objectives for establishing, implementing,
  • DA systematic approach for establishing, implementing, operating, monitoring, reviewing,

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    11% (5)
  • C
    7% (3)
  • D
    80% (35)

Explanation

The standard definition of ISMS is a systematic approach for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security to achieve business objectives. This definition is given in clause 3.17 of ISO/IEC 27001:2022, and it describes the main components and purpose of an ISMS. An ISMS is not a project-based approach, as it is an ongoing process that requires continual improvement. An ISMS is not a company wide business objective, as it is a management system that supports the organization's objectives. An ISMS is not an information security systematic approach, as it is a broader concept that encompasses the organization's context, risks, controls, and performance.

Topics

#ISMS#ISO 27001#information security management system#systematic approach

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice