nerdexam
(ISC)2

CCSP · Question #164

An audit against the ________ will demonstrate that an organization has 琣dequate security controls to meet its ISO 27001 requirements.

The correct answer is C. ISO 27002 certification criteria. ISO 27002 provides the specific guidelines and best practices for implementing information security controls that enable an organization to meet the overarching requirements of ISO 27001 certification.

Submitted by naveen.iyer· Apr 18, 2026Legal, Risk and Compliance

Question

An audit against the ________ will demonstrate that an organization has 琣dequate security controls to meet its ISO 27001 requirements.

Options

  • ASAS 70 standard
  • BSSAE 16 standard
  • CISO 27002 certification criteria
  • DNIST SP 800-53

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    6% (1)
  • C
    89% (16)

Why each option

ISO 27002 provides the specific guidelines and best practices for implementing information security controls that enable an organization to meet the overarching requirements of ISO 27001 certification.

ASAS 70 standard

SAS 70 (Statement on Auditing Standards No. 70) was an auditing standard focused on the internal controls of service organizations but has been superseded by SSAE 16.

BSSAE 16 standard

SSAE 16 (Statement on Standards for Attestation Engagements No. 16) is an auditing standard for reporting on controls at a service organization, now largely replaced by SSAE 18, and is not directly tied to demonstrating compliance with ISO 27001.

CISO 27002 certification criteriaCorrect

An audit against the ISO 27002 certification criteria specifically details the recommended information security controls and best practices that an organization should implement to satisfy the requirements of ISO 27001, which is the standard for an Information Security Management System (ISMS). Demonstrating adherence to ISO 27002 directly shows that the organization has adequate security controls to achieve ISO 27001 compliance.

DNIST SP 800-53

NIST SP 800-53 is a publication by the National Institute of Standards and Technology that provides a catalog of security and privacy controls for federal information systems, which is a U.S. federal standard, not directly aligned with international ISO 27001 requirements for certification.

Concept tested: ISO 27001/27002 relationship

Source: https://www.iso.org/standard/74540.html

Topics

#ISO 27001#ISO 27002#Compliance#Audit

Community Discussion

No community discussion yet for this question.

Full CCSP Practice