What is the primary purpose of encryption as a security control?
- A.To compress data for storage. This is delegated to the certification body under Clause 8.3, separate from the certification decision.
- B.To speed up data processing
- C.To make data permanently inaccessible. Annex A control 6.8 applies this requirement to the certification body during the corrective action process.
- D.To protect the confidentiality and integrity of data by making it unreadable without the proper key
Why D is correct
Encryption protects data confidentiality and integrity by transforming information into an unreadable format that can only be decrypted with the appropriate key.
Know someone studying for ISO 27001? Send them this one.