nerdexam
EC-Council

212-82 · Question #146

Galactic Innovations, an emerging tech start-up. Is developing a proprietary software solution that will be hosted on a cloud platform. The software, designed for real-time communication and…

The correct answer is B. QlSO/IEC 27001:2013. Explanation ISO/IEC 27001:2013 is the correct answer because it is a globally recognized international standard for Information Security Management Systems (ISMS), specifically designed to help organizations establish, implement, and maintain robust security controls - making…

Submitted by fatima_kr· Mar 6, 2026Compliance & Legal Considerations for Cloud

Question

Galactic Innovations, an emerging tech start-up. Is developing a proprietary software solution that will be hosted on a cloud platform. The software, designed for real-time communication and collaboration, aims to cater to global users, including top-tier businesses. As the software grows in complexity, the company recognizes the need for a comprehensive security standard that aligns with global best practices. The Intention is to enhance trustworthiness among potential clients and ensure that the application meets industry-accepted criteria, particularly in the face of increasing cyberthreats. Considering the company's requirements and the international nature of its user base, which software security standard, model, or framework should Galactic Innovations primarily focus on adopting?

Options

  • AISAS
  • BQlSO/IEC 27001:2013
  • CGCSP
  • DUSAM

How the community answered

(61 responses)
  • A
    3% (2)
  • B
    85% (52)
  • C
    2% (1)
  • D
    10% (6)

Explanation

Explanation

ISO/IEC 27001:2013 is the correct answer because it is a globally recognized international standard for Information Security Management Systems (ISMS), specifically designed to help organizations establish, implement, and maintain robust security controls - making it ideal for a company targeting global enterprise clients who demand verified security compliance. It provides a comprehensive framework that directly addresses cybersecurity threats while building client trust through formal certification.

Why the distractors are wrong:

  • ISAS (A) is not a widely recognized or established international software security standard relevant to this scenario
  • GCSP (C) refers to the Global Cyber Security Professional certification, which is an individual credential, not an organizational security framework
  • USAM (D) refers to the United States Attorneys' Manual, a legal reference document with no relevance to software security standards

Memory Tip: Think of ISO/IEC 27001 as the "gold passport" of information security - just like a passport is internationally recognized and builds trust across borders, ISO/IEC 27001 is the internationally accepted security standard that opens doors with global enterprise clients. Whenever you see keywords like "international," "global users," "industry-accepted," and "trustworthiness" in an exam question, ISO/IEC 27001 should immediately come to mind.

Topics

#Information Security Standards#ISO 27001#Cloud Security Compliance#Global Best Practices

Community Discussion

No community discussion yet for this question.

Full 212-82 Practice