nerdexam
(ISC)2

CAP · Question #127

ISO 17799 has two parts. The first part is an implementation guide with guidelines on how to build a comprehensive information security infrastructure and the second part is an auditing guide based…

The correct answer is A. Information security policy for the organization C. Business continuity management D. System developmentand maintenance E. Personnel security. ISO 17799 defines several information security domains; 'System architecture management' is not one of them, while security policy, business continuity, system development, and personnel security are valid domains.

Selection and Approval of Framework, Security, and Privacy Controls

Question

ISO 17799 has two parts. The first part is an implementation guide with guidelines on how to build a comprehensive information security infrastructure and the second part is an auditing guide based on requirements that must be met for an organization to be deemed compliant with ISO 17799. What are the ISO 17799 domains? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AInformation security policy for the organization
  • BSystem architecture management
  • CBusiness continuity management
  • DSystem developmentand maintenance
  • EPersonnel security

How the community answered

(44 responses)
  • A
    86% (38)
  • B
    14% (6)

Why each option

ISO 17799 defines several information security domains; 'System architecture management' is not one of them, while security policy, business continuity, system development, and personnel security are valid domains.

AInformation security policy for the organizationCorrect

Information security policy is one of the 11 core domains of ISO 17799, establishing the management direction and support for information security across the organization.

BSystem architecture management

System architecture management is not a domain defined within ISO 17799; the standard does not include an architecture management category among its 11 domains.

CBusiness continuity managementCorrect

Business continuity management is a defined ISO 17799 domain focused on preventing business activity interruptions and protecting critical processes from disasters.

DSystem developmentand maintenanceCorrect

System development and maintenance is an ISO 17799 domain covering security requirements in information systems throughout their lifecycle.

EPersonnel securityCorrect

Personnel security is an ISO 17799 domain addressing security responsibilities during recruitment, employment, and termination of staff.

Concept tested: ISO 17799 information security domains identification

Source: https://www.iso.org/standard/39612.html

Topics

#ISO 17799#Information Security Standards#Security Controls#Compliance

Community Discussion

No community discussion yet for this question.

Full CAP Practice