Question 1 of 30
SecureFuture Solutions, a burgeoning cybersecurity firm specializing in threat intelligence, is attempting to bolster its Information Security Management System (ISMS) to align with ISO 27002:2022. However, the firm is encountering significant challenges. Different departments operate independently, leading to inconsistencies in data handling procedures, security protocols, and risk assessments. The sales team uses a different CRM with weaker security controls than the development team’s secure coding environment. The HR department stores sensitive employee data on a shared drive with inadequate access controls, while the finance department employs robust encryption for all financial transactions. This fragmented approach has resulted in several near-miss security incidents and a growing concern among senior management. The Chief Information Security Officer (CISO) recognizes that the current ISMS lacks a cohesive structure and fails to effectively integrate security controls across the organization. Which quality management principle, as defined within ISO 27002:2022 and ISO 9001:2015, is most directly being undermined by SecureFuture Solutions\' current operational model, and what practical steps should the CISO take to address this deficiency?
The 'Process Approach' is being undermined. The CISO should map out key information security processes, identify their interdependencies, establish clear responsibilities and authorities, define measurable objectives, implement training programs, and conduct regular audits to ensure consistent application of security controls across all departments.
'Customer Focus' is the primary issue. The CISO needs to conduct extensive customer surveys to understand their security expectations and tailor security controls to meet those specific needs, even if it means implementing different security levels for different clients.
'Leadership' is the most significant gap. The CISO must focus on obtaining explicit endorsements and directives from senior management to enforce a top-down security mandate, regardless of departmental operational differences.
'Relationship Management' is lacking. The CISO should prioritize building stronger relationships with external vendors and consultants to outsource security responsibilities, thereby minimizing internal inconsistencies.

Preparing for ISO 27002:2022 – Information Security Controls? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free