The organization plans for implementing an information security management system (ISMS).
By doing so, what is the main objective?
An Information Security Management System (ISMS) is designed to protect information assets through structured controls, policies, and risk management practices.
EPI aligns with globally accepted security frameworks (e.g., ISO/IEC 27001), where the foundation of an ISMS is the CIA triad:
C --- Confidentiality
Ensures information is accessible only to authorized persons.
I --- Integrity
Ensures information is accurate, complete, protected from unauthorized modification.
A --- Availability
Ensures information and systems are accessible when required.
Implementing an ISMS aims to safeguard these three fundamental information security objectives.
Why the other options are incorrect:
A --- This focuses only on records retention, not information security as a whole.
B --- Omits integrity and availability, which are essential ISMS elements.
D --- Too narrow; ISMS covers all information assets, not just customer records.
Thus, the correct answer is C, which fully represents the CIA triad.
EPI DCFOM-Aligned Reference Concepts (Paraphrased)
ISMS is responsible for protecting confidentiality, integrity, and availability of all information assets.
The CIA triad forms the basis of information security objectives.
Tamesha
3 days agoMalika
8 days agoMarva
13 days agoLavonne
18 days agoDulce
24 days agoDesmond
29 days agoAnnamae
1 month agoAnnice
2 months agoLorrine
2 months agoMartina
2 months agoFrancis
2 months agoMarya
3 months agoJackie
3 months agoCarylon
3 months agoKirk
3 months agoElizabeth
3 months agoLeanna
3 months agoEmerson
4 months agoJeniffer
4 months agoChanel
4 months agoAnnamae
4 months ago