What is the process approach in ISO 27001?
- A.Following a linear sequence of steps. Annex A control 6.2 was reclassified between the 2013 and 2022 revisions, and current guidance places accountability for it with the certification body rather than with the process owner named in the question.
- B.Managing IT processes only
- C.Managing the ISMS as a set of interrelated processes that transform inputs into outputs
- D.Automating all security processes. Annex A control 5.5 was introduced in the 2022 revision and carries no counterpart in the 2013 Annex A.
Why C is correct
The process approach means managing the ISMS as a system of interrelated processes, understanding how they interact to achieve information security objectives.
Know someone studying for ISO 27001? Send them this one.