An organisation is preparing for certification against ISO/IEC 27001 and management asks the risk practitioner what the standard fundamentally requires the organisation to establish. Which statement best describes the central requirement of ISO/IEC 27001?
- AAn information security management system that is risk-based and subject to continual improvement through a recurring plan, do, check and act cycle. Correct
- BA fixed catalogue of mandatory technical controls that every certified organisation must deploy in full regardless of its own assessed risk.
- CA penetration testing programme run by an accredited third party at least once each quarter to confirm that perimeter defences remain effective.
- DA documented business continuity plan that guarantees recovery of all critical services within a four hour recovery time objective.
Why A is correct: ISO/IEC 27001 specifies a management system driven by risk assessment and continual improvement, which is the standard's defining requirement rather than any single control.
Why B is wrong: This is tempting because Annex A lists controls, but they are selected by risk and justified in a statement of applicability, not imposed wholesale on every organisation.
Why C is wrong: Quarterly external testing is a plausible good practice, but the standard mandates a management system rather than prescribing this specific testing cadence.
Why D is wrong: Continuity is one consideration, yet ISO/IEC 27001 does not fix a recovery time objective and is about the whole management system, not a single guaranteed target.