Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security

Which international standard specifies requirements for establishing, implementing, maintaining and continually improving an Information Security Management System (ISMS), often used by software firms to demonstrate security governance?

ISO/IEC 27001 is the standard for an Information Security Management System. It sets requirements for establishing, implementing, maintaining and continually improving information security controls, unlike ISO 9001 for quality, ISO 14001 for environment or ISO 45001 for occupational safety.

  1. AISO/IEC 27001Correct
  2. BISO 9001
  3. CISO 14001
  4. DISO 45001

Explanation

ISO/IEC 27001 is the ISMS standard. ISO 9001 covers quality management, ISO 14001 environmental management and ISO 45001 occupational health and safety, so they do not address information security.

Did you get it right without looking?

One question tells you little. A timed set on Softwares and Software Security shows your real accuracy, how long you take and where you lose marks.

More Softwares and Software Security questions