712-50 Question 41
Single answerBe familiar with international security and risk standards such as ISO 27000, and 31000 seriesA multinational manufacturing company has grown through acquisitions and now operates with different regional risk practices and inconsistent information security controls. The board has asked the new CISO to create a unified, enterprise-wide approach that aligns cyber risk decisions with business objectives, while also establishing a certifiable information security management program for major customer contracts. Which approach should the CISO take FIRST to best satisfy both requirements?
- A
Adopt ISO/IEC 31000 as the enterprise risk management framework to define risk principles, governance, and treatment processes, and use ISO/IEC 27001/27002 to implement and certify the information security management system and associated controls
- B
Implement ISO/IEC 27002 as the primary enterprise risk framework because its control catalog is sufficient to replace broader business risk governance and board-level risk criteria
- C
Pursue ISO/IEC 27701 certification first, because privacy management certification will automatically satisfy customer expectations for information security and enterprise risk management
- D
Use ISO/IEC 27005 as the sole framework for enterprise risk governance, because it is designed to replace both ISO/IEC 31000 and ISO/IEC 27001 in multinational organizations
Show answer and explanation
Correct answer: A
Explanation
The best answer is to use ISO 31000 and the ISO/IEC 27000-series together, each for its intended purpose. ISO 31000 gives senior leadership a structure for enterprise risk management, including principles, integration into governance, risk assessment, treatment, communication, monitoring, and continual improvement. This is important in a post-acquisition environment where the organization needs consistent risk criteria and governance across business units. For information security, ISO/IEC 27001 is the key certifiable standard for an ISMS, and ISO/IEC 27002 provides implementation guidance for controls. In practice, many organizations also use ISO/IEC 27005 to support information security risk assessment within the ISMS, but it does not replace enterprise risk management under ISO 31000. This approach aligns with the intended use of the standards: ISO 31000 for organization-wide risk management and ISO/IEC 27001/27002 for a certifiable and operational security program.
- A. Correct.
Correct. ISO 31000 provides principles and guidelines for enterprise risk management across the organization, helping align risk decisions with business objectives, governance, and stakeholder expectations. ISO/IEC 27001 is the certifiable standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS), while ISO/IEC 27002 provides guidance on selecting and implementing information security controls. This combination addresses both board-level enterprise risk management and the requirement for a certifiable security program for customers.
- B. Incorrect.
Incorrect. ISO/IEC 27002 is a guidance standard for information security controls, not a complete enterprise risk management framework. It does not replace broader governance, risk appetite, context-setting, and decision-making structures covered by ISO 31000. A common misconception is to treat a control catalog as equivalent to enterprise risk governance.
- C. Incorrect.
Incorrect. ISO/IEC 27701 extends privacy information management on top of ISO/IEC 27001 and ISO/IEC 27002, but it is not a substitute for an enterprise risk management framework. It may help with privacy obligations, but it does not automatically meet overall information security certification requirements or establish board-level enterprise risk management across all risk domains.
- D. Incorrect.
Incorrect. ISO/IEC 27005 provides guidance for information security risk management and is useful within the ISMS context, but it does not replace ISO 31000 for enterprise-wide risk governance, nor does it replace ISO/IEC 27001 as the certifiable ISMS standard. This option reflects the mistaken belief that a security-specific risk methodology can fully substitute for enterprise risk governance and certification requirements.