Exam Cybersecurity Fundamentals Specialist All QuestionsBrowse all questions from this exam
Question 71

What is the FIRST step required in implementing ISO 27001?

    Correct Answer: B

    The first step in implementing ISO 27001 is defining an information security policy. This policy sets the scope and context for the entire Information Security Management System (ISMS), outlining the organization's commitment to information security, its objectives, and the framework within which security will be managed. Without a clear policy, the subsequent steps lack direction and coherence. This foundational document guides the creation of other necessary components, including the security management organization, controls, and risk assessments.

Discussion
ac873d6Option: A

ISO/IEC 27001 provides requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System. Key in on the words “security management system”. ISO 27001 provides a list of commonly accepted controls to be used as a reference for establishing security requirements.