The organization plans for implementing an information security management system (ISMS).
By doing so, what is the main objective?
An Information Security Management System (ISMS) is designed to protect information assets through structured controls, policies, and risk management practices.
EPI aligns with globally accepted security frameworks (e.g., ISO/IEC 27001), where the foundation of an ISMS is the CIA triad:
C --- Confidentiality
Ensures information is accessible only to authorized persons.
I --- Integrity
Ensures information is accurate, complete, protected from unauthorized modification.
A --- Availability
Ensures information and systems are accessible when required.
Implementing an ISMS aims to safeguard these three fundamental information security objectives.
Why the other options are incorrect:
A --- This focuses only on records retention, not information security as a whole.
B --- Omits integrity and availability, which are essential ISMS elements.
D --- Too narrow; ISMS covers all information assets, not just customer records.
Thus, the correct answer is C, which fully represents the CIA triad.
EPI DCFOM-Aligned Reference Concepts (Paraphrased)
ISMS is responsible for protecting confidentiality, integrity, and availability of all information assets.
The CIA triad forms the basis of information security objectives.
Annice
7 days agoLorrine
13 days agoMartina
18 days agoFrancis
23 days agoMarya
28 days agoJackie
1 month agoCarylon
1 month agoKirk
1 month agoElizabeth
2 months agoLeanna
2 months agoEmerson
2 months agoJeniffer
2 months agoChanel
2 months agoAnnamae
2 months ago