A global e-commerce company has a well-established ISO/IEC 27001 certified Information Security Management System (ISMS). To better align with global privacy regulations like GDPR and CCPA, the company decides to implement ISO/IEC 27701. How does ISO/IEC 27701 relate to their existing ISMS?
-
A
It replaces the existing ISMS with a more privacy-focused framework.
-
B
It operates as a separate, parallel framework exclusively for the legal department.
-
C
It serves as a privacy-specific extension, enhancing the ISMS to become a Privacy Information Management System (PIMS).
-
D
It is a certification that is only applicable to data processors, not data controllers.