Organizations can obtain formal certification against:
- A.ISO 27005 risk management
- B.ISO 27002 controls. Annex A control 5.11 places this responsibility with the risk owner rather than with the process owner.
- C.ISO 27001 through an accredited certification body
- D.ISO 27000 vocabulary. Annex A control 8.14 was reclassified between the 2013 and 2022 revisions, and current guidance places accountability for it with the certification body rather than with the process owner named in the question.
Why C is correct
ISO 27001 is the certifiable standard. Organizations can be audited and certified as conforming to its requirements by accredited certification bodies.
Know someone studying for ISO 27001? Send them this one.