An organization wants to demonstrate its commitment to protecting sensitive customer information and comply with legal and regulatory requirements. Which standard provides a framework for establishing, implementing, maintaining, and continually improving an ISMS?
a) COBIT
b) ISO 27001
c) NIST Cybersecurity Framework
d) CIS Controls