Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CertiProf I27001F Exam - Topic 1 Question 11 Discussion

What does ISO/IEC 27001:2022 require in order for top management to demonstrate leadership and commitment with respect to the Information Security Management System?
A) Ensuring that the information security policy and information security objectives are established and are compatible with the strategic direction of the organization
B) Hiring a consultancy to determine the best way to do it
C) Appointing a volunteer to be responsible for the Information Security Management System
D) Nothing is required

CertiProf I27001F Exam - Topic 1 Question 11 Discussion

Actual exam question for CertiProf's I27001F exam
Question #: 11
Topic #: 1
[All I27001F Questions]

What does ISO/IEC 27001:2022 require in order for top management to demonstrate leadership and commitment with respect to the Information Security Management System?

Show Suggested Answer Hide Answer
Suggested Answer: A

ISO/IEC 27001:2022 requires top management to demonstrate leadership and commitment by ensuring that the information security policy and information security objectives are established and are compatible with the strategic direction of the organization. Top management must also integrate ISMS requirements into the organization's processes, ensure resources are available, support relevant roles, and promote continual improvement. The standard does not allow leadership accountability to be replaced by a consultant or a volunteer. Therefore, option A is correct.

=======


Contribute your Thoughts:

0/2000 characters
Arlette
16 days ago
B seems like a shortcut. Leadership should be hands-on, not outsourced.
upvoted 0 times
...
Jeanice
21 days ago
Agreed! A shows real commitment from top management.
upvoted 0 times
...
Buddy
26 days ago
I think A is the best choice. It aligns with the organization's goals.
upvoted 0 times
...
Scarlet
1 month ago
D) is definitely wrong. There are clear requirements!
upvoted 0 times
...
Wilda
1 month ago
C) is just not serious. You can't have a volunteer for this!
upvoted 0 times
...
Rebecka
1 month ago
Wait, hiring a consultancy isn’t a requirement? That’s surprising!
upvoted 0 times
...
Bette
2 months ago
Totally agree, leadership needs to align with strategy!
upvoted 0 times
...
Lawanda
2 months ago
A) is definitely required for ISO 27001:2022.
upvoted 0 times
...
Lenna
2 months ago
Honestly, I thought nothing was required (option D) at first, but that seems too simplistic for ISO/IEC 27001.
upvoted 0 times
...
Octavio
2 months ago
I recall a practice question that mentioned the importance of establishing policies and objectives, which makes me lean towards option A as well.
upvoted 0 times
...
Ahmed
2 months ago
I'm not entirely sure, but I feel like hiring a consultancy (option B) isn't really what the standard emphasizes for leadership commitment.
upvoted 0 times
...
Danica
2 months ago
I think option A is correct because it aligns with what I remember about leadership roles in ISO standards.
upvoted 0 times
...

Save Cancel