A multinational retailer already certified to ISO 27001 wants to adopt a risk assessment standard that integrates cleanly with its existing information security management system without introducing a conflicting risk vocabulary. Which standard is the most appropriate choice?
- AISO 27005, because it provides information security risk guidance designed to support the ISO 27001 management system already in place. Correct
- BFAIR, because it supplies a taxonomy for quantifying cyber loss that can replace the existing management system risk process.
- COCTAVE Allegro, because it offers a self-directed workshop method that operates independently of any existing management system.
- DPCI DSS, because it defines a prescriptive control baseline that the retailer can substitute for its current risk process.
Why A is correct: ISO 27005 is purpose-built to support an ISO 27001 information security management system, so its terms and process align with the retailer's existing certification.
Why B is wrong: It is tempting as a quantification model, but positioning it to replace the existing process introduces the very vocabulary conflict the retailer wants to avoid.
Why C is wrong: It is plausible as an established assessment method, yet its self-directed approach sits apart from ISO and does not integrate with the certified management system.
Why D is wrong: It is attractive given the retail payment context, but PCI DSS is a control mandate for card data, not a risk assessment standard that integrates with ISO 27001.