ExamGecko
Question list
Search
Search

Related questions

Question 221 - CISA discussion

Report
Export

Which of the following is the MAIN purpose of an information security management system?

A.
To identify and eliminate the root causes of information security incidents
Answers
A.
To identify and eliminate the root causes of information security incidents
B.
To enhance the impact of reports used to monitor information security incidents
Answers
B.
To enhance the impact of reports used to monitor information security incidents
C.
To keep information security policies and procedures up-to-date
Answers
C.
To keep information security policies and procedures up-to-date
D.
To reduce the frequency and impact of information security incidents
Answers
D.
To reduce the frequency and impact of information security incidents
Suggested answer: D

Explanation:

:The main purpose of an information security management system (ISMS) is to reduce the frequency and impact of information security incidents. An ISMS is a systematic approach to managing information security risks, policies, procedures, and controls within an organization. An ISMS aims to ensure the confidentiality, integrity, and availability of information assets, as well as to comply with relevant laws and regulations. The other options are not the main purpose of an ISMS, but rather some of its possible benefits or components.Reference:

CISA Review Manual (Digital Version), Chapter 7, Section 7.11

CISA Review Questions, Answers & Explanations Database, Question ID 205

asked 18/09/2024
Panayiotis Markatos
51 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first