LEAD-AUDITOR · Question #9
What is the standard definition of ISMS?
The correct answer is D. A systematic approach for establishing, implementing, operating, monitoring, reviewing,. The standard definition of ISMS is a systematic approach for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security to achieve business objectives. This definition is given in clause 3.17 of ISO/IEC 27001:202
Question
What is the standard definition of ISMS?
Options
- AIs an information security systematic approach to achieve business objectives for implementation,
- BA company wide business objectives to achieve information security awareness for establishing,
- CA project-based approach to achieve business objectives for establishing, implementing,
- DA systematic approach for establishing, implementing, operating, monitoring, reviewing,
How the community answered
(44 responses)- A2% (1)
- B11% (5)
- C7% (3)
- D80% (35)
Explanation
The standard definition of ISMS is a systematic approach for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security to achieve business objectives. This definition is given in clause 3.17 of ISO/IEC 27001:2022, and it describes the main components and purpose of an ISMS. An ISMS is not a project-based approach, as it is an ongoing process that requires continual improvement. An ISMS is not a company wide business objective, as it is a management system that supports the organization's objectives. An ISMS is not an information security systematic approach, as it is a broader concept that encompasses the organization's context, risks, controls, and performance.
Topics
Community Discussion
No community discussion yet for this question.