A software technology vendor has established a formal Information Security Management System (ISMS) to safeguard its cloud services. To satisfy international enterprise clients requiring proof of security compliance and receive an officially recognized certificate, the vendor must undergo an independent third-party evaluation. Which of the following activities should the vendor initiate?
- An ISO/IEC 27001 Stage 2 audit conducted by an accredited external certification bodyAnswer
- BAn internal security attestation review performed by the vendor's chief information security officer
- CA self-administered PCI DSS Self-Assessment Questionnaire to evaluate overall governance controls
- DA third-party vulnerability assessment without an accompanying control design and operational audit
Answer
An ISO/IEC 27001 Stage 2 audit conducted by an accredited external certification body
The correct answer specifies an ISO/IEC 27001 Stage 2 audit conducted by an accredited external certification body. ISO/IEC 27001 certification requires a two-stage independent audit: Stage 1 reviews documentation readiness, and Stage 2 assesses the actual operational effectiveness and compliance of the Information Security Management System (ISMS) to grant official certification.
Step-by-Step Solution
Key Concept
Independent Third-Party Audits and Security Certifications