CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security
Which international standard specifies requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS), often used by software firms to demonstrate security governance?
ISO/IEC 27001 is the standard for an Information Security Management System. It sets requirements for establishing, implementing, maintaining and continually improving information security controls, unlike ISO 9001 for quality, ISO 14001 for environment or ISO 45001 for occupational safety.
- AISO/IEC 27001Correct
- BISO 9001
- CISO 14001
- DISO 45001
Explanation
ISO/IEC 27001 is the ISMS standard. ISO 9001 covers quality management, ISO 14001 environmental management and ISO 45001 occupational health and safety, so they do not address information security.
Did you get it right without looking?
One question tells you little. A timed set on Softwares and Software Security shows your real accuracy, how long you take and where you lose marks.
More Softwares and Software Security questions
- A listed company's vendor delivered billing software that passed all functional tests. After deployment, an attacker exploited an unvalidate…
- A program copies more data into a fixed-size memory area than it can hold, overwriting adjacent memory and allowing an attacker to run injec…
- Under the Information Technology Act, 2000, a software developer in Pune deliberately inserts a hidden routine into a client's accounting so…
- Meridian Pay's team follows a secure software development life cycle. During the design phase, it systematically identifies assets, entry po…
- A company deposits the source code of bespoke software with a neutral third party, to be released to the customer if the vendor becomes inso…
- A company holds sensitive personal data in its software and suffers a breach because it did not maintain reasonable security practices. Whic…