Question 1 of 30
A multinational technology firm, \"Innovatech Solutions,\" is establishing its Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2013. The firm operates in several jurisdictions, including the European Union and the United States, and handles sensitive customer data and intellectual property. During the initial phase of ISMS implementation, the organization needs to systematically identify and document the information security requirements of its various stakeholders. Which of the following approaches best reflects the mandatory requirements of ISO/IEC 27001:2013 for understanding the needs and expectations of interested parties?
Conduct a comprehensive review of all applicable legal and regulatory frameworks (e.g., GDPR, CCPA), contractual obligations with clients and partners, and internal policies to identify explicit and implicit information security requirements from all relevant interested parties.
Primarily focus on the requirements of the highest paying clients and the most stringent internal IT security policies, assuming these encompass the majority of critical stakeholder needs.
Rely on the IT department's existing security protocols and assume that these are sufficient to meet the diverse needs of all interested parties without explicit external consultation.
Document only the requirements that are directly mandated by ISO/IEC 27001:2013 itself, disregarding any sector-specific regulations or customer-specific contractual clauses.

Preparing for ISO/IEC 27001:2013 Information Security Management Systems - Requirements Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free