According to ISO 27001, which of the following is the primary purpose of monitoring, measurement, analysis, and evaluation of the ISMS?
-
A
To generate detailed reports exclusively for the annual external certification audit.
-
B
To evaluate information security performance and the effectiveness of the ISMS.
-
C
To select and procure new security hardware and software based on performance data.
-
D
To identify and discipline employees who do not comply with security policies.