nerdexam
(ISC)2

CAP · Question #309

Numerous information security standards promote good security practices and define frameworks or systems to structure the analysis and design for managing information security controls. Which of the…

The correct answer is A. Human resources security B. Organization of information security C. Risk assessment and treatment. Options A (Human Resources Security), B (Organization of Information Security), and C (Risk Assessment and Treatment) are all domains/clauses found within the international information security standards ISO/IEC 27001 and ISO/IEC 27002. These are globally recognized standards…

Selection and Approval of Framework, Security, and Privacy Controls

Question

Numerous information security standards promote good security practices and define frameworks or systems to structure the analysis and design for managing information security controls. Which of the following are the international information security standards? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AHuman resources security
  • BOrganization of information security
  • CRisk assessment and treatment
  • DAU audit and accountability

How the community answered

(16 responses)
  • A
    88% (14)
  • D
    13% (2)

Explanation

Options A (Human Resources Security), B (Organization of Information Security), and C (Risk Assessment and Treatment) are all domains/clauses found within the international information security standards ISO/IEC 27001 and ISO/IEC 27002. These are globally recognized standards developed by the International Organization for Standardization (ISO). Option D - 'AU Audit and Accountability' - is a control family from NIST SP 800-53, which is a U.S. federal government standard, not an international standard. Therefore, A, B, and C are the correct answers.

Topics

#International Standards#ISO 27001#Information Security Controls#Risk Management

Community Discussion

No community discussion yet for this question.

Full CAP Practice