Which framework is structured as an ISMS with Annex A controls?

Prepare for the Internal Auditing and Cybersecurity Exam with flashcards and multiple choice questions. Each question offers detailed explanations. Ace your test with confidence!

Multiple Choice

Which framework is structured as an ISMS with Annex A controls?

Explanation:
ISO/IEC 27001 is built around an Information Security Management System (ISMS), a formal, ongoing approach to governing information security risks. The standard explicitly includes Annex A, a catalog of controls that organizations can select and implement to address identified risks. This combination of an ISMS framework plus a defined set of controls in Annex A is what distinguishes ISO 27001. Other frameworks describe risk management or governance approaches and offer controls, but they don’t present themselves as an ISMS with Annex A controls. Therefore, ISO 27001 is the framework that fits this description.

ISO/IEC 27001 is built around an Information Security Management System (ISMS), a formal, ongoing approach to governing information security risks. The standard explicitly includes Annex A, a catalog of controls that organizations can select and implement to address identified risks. This combination of an ISMS framework plus a defined set of controls in Annex A is what distinguishes ISO 27001. Other frameworks describe risk management or governance approaches and offer controls, but they don’t present themselves as an ISMS with Annex A controls. Therefore, ISO 27001 is the framework that fits this description.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy