CCAK · Question #53
You have been assigned the implementation of an ISMS, whose scope must cover both on premise and cloud infrastructure. Which of the following is your BEST option?
The correct answer is B. Implement ISO/IEC 27001 and complement it with additional controls from ISO/IEC 27017. ISO/IEC 27001 is the certifiable ISMS standard that provides the management framework (not ISO/IEC 27002, which is only a controls catalog and not certifiable). For environments that include cloud infrastructure, ISO/IEC 27017 is the appropriate supplement - it provides…
Question
You have been assigned the implementation of an ISMS, whose scope must cover both on premise and cloud infrastructure. Which of the following is your BEST option?
Options
- AImplement ISO/IEC 27002 and complement it with additional controls from the CCM.
- BImplement ISO/IEC 27001 and complement it with additional controls from ISO/IEC 27017.
- CImplement ISO/IEC 27001 and complement it with additional controls from ISO/IEC 27002.
- DImplement ISO/IEC 27001 and complement it with additional controls from the NIST SP 800-145.
How the community answered
(39 responses)- A13% (5)
- B79% (31)
- C5% (2)
- D3% (1)
Explanation
ISO/IEC 27001 is the certifiable ISMS standard that provides the management framework (not ISO/IEC 27002, which is only a controls catalog and not certifiable). For environments that include cloud infrastructure, ISO/IEC 27017 is the appropriate supplement - it provides cloud-specific security controls built on top of ISO/IEC 27002's catalog, tailored for both cloud service providers and customers. Option A is incorrect because ISO/IEC 27002 is not an ISMS standard. Option C uses 27002 as a supplement, but 27002 contains no cloud-specific controls. Option D is incorrect because NIST SP 800-145 is simply a definitional document for cloud computing, not a controls framework.
Topics
Community Discussion
No community discussion yet for this question.