When aligning vulnerability management practices with industry frameworks, which of the following is the BEST choice to ensure that an organization's information security management system encompasses a broad set of security controls and risk management?
ISO/IEC 27001 is the best choice because it provides a model for establishing, implementing, maintaining, and continually improving an information security management system (ISMS). This standard is designed to ensure the selection of adequate and proportionate security controls that protect information assets and give confidence to interested parties. ISO/IEC 27002 provides guidelines for organizational information security standards and information security management practices including the selection, implementation, and management of controls, but does not outline a management system framework itself.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an Information Security Management System (ISMS)?
Open an interactive chat with Bash
What are security controls in the context of ISO/IEC 27001?