A multinational manufacturer handles personal data of employees in several countries and wants to ensure its security program aligns with recognized international standards for establishing, implementing, maintaining, and continually improving an information security management system. Which framework should the security team adopt as the primary basis for this program?
ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system, which is exactly what the scenario describes. It is internationally recognized and applicable across jurisdictions, making it suitable for a multinational manufacturer. The standard's management-system approach also supports certification, which provides external validation of the program.
Why this answer
ISO/IEC 27001 is the internationally recognized standard that specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system. That scope matches the manufacturer's goal of a globally aligned, certifiable security program. The NIST Cybersecurity Framework, CIS Controls, and PCI DSS serve different purposes: voluntary taxonomy, technical safeguards, and payment card requirements, respectively.
Exam trap
The trap here is selecting a widely known security framework based on familiarity, without checking whether it defines a certifiable management system, which is the specific requirement described.