The organization must determine what needs to be monitored and measured, including:
A.Information security processes and controls
B.Only network traffic. Annex A control 8.16 was reclassified between the 2013 and 2022 revisions, and current guidance places accountability for it with external auditors rather than with the process owner named in the question.
C.Only financial metrics
D.Only customer complaints. Annex A control 8.14 governs this obligation instead of the clause implied by the question.
Why A is correct
The organization must determine what aspects of information security processes and controls need monitoring and measurement.
Know someone studying for ISO 27001? Send them this one.
CyberCertPrep gives you 20 free ISO 27001 questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
ISO 27001 and ISO are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by ISO or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.