nerdexam
(ISC)2

CCSP · Question #343

The ISO/IEC 27001:2013 security standard contains 14 different domains that cover virtually all areas of IT operations and procedures. Which of the following is NOT one of the domains listed in the…

The correct answer is A. Legal. The ISO/IEC 27001:2013 standard includes a domain for 'Legal, statutory, regulatory and contractual requirements' but not a standalone 'Legal' domain.

Submitted by ricky.ec· Apr 18, 2026Legal, Risk and Compliance

Question

The ISO/IEC 27001:2013 security standard contains 14 different domains that cover virtually all areas of IT operations and procedures. Which of the following is NOT one of the domains listed in the standard? Response:

Options

  • ALegal
  • BManagement
  • CAssets
  • DSupplier Relationships

How the community answered

(25 responses)
  • A
    88% (22)
  • C
    8% (2)
  • D
    4% (1)

Why each option

The ISO/IEC 27001:2013 standard includes a domain for 'Legal, statutory, regulatory and contractual requirements' but not a standalone 'Legal' domain.

ALegalCorrect

ISO/IEC 27001:2013 includes a domain specifically for 'Compliance' (A.18), which covers 'Legal, statutory, regulatory and contractual requirements,' but 'Legal' itself is not a standalone domain title among the 14 main control categories specified in the standard.

BManagement

'Organization of information security' (A.6) is a domain in ISO/IEC 27001:2013 covering management aspects.

CAssets

'Asset management' (A.8) is a dedicated domain in ISO/IEC 27001:2013.

DSupplier Relationships

'Supplier relationships' (A.15) is a dedicated domain in ISO/IEC 27001:2013.

Concept tested: ISO/IEC 27001:2013 domains

Source: https://www.isms.online/iso-27001/controls/

Topics

#ISO 27001#Information Security Standards#Compliance#Risk Management

Community Discussion

No community discussion yet for this question.

Full CCSP Practice