CCSP · Question #343
The ISO/IEC 27001:2013 security standard contains 14 different domains that cover virtually all areas of IT operations and procedures. Which of the following is NOT one of the domains listed in the…
The correct answer is A. Legal. The ISO/IEC 27001:2013 standard includes a domain for 'Legal, statutory, regulatory and contractual requirements' but not a standalone 'Legal' domain.
Question
The ISO/IEC 27001:2013 security standard contains 14 different domains that cover virtually all areas of IT operations and procedures. Which of the following is NOT one of the domains listed in the standard? Response:
Options
- ALegal
- BManagement
- CAssets
- DSupplier Relationships
How the community answered
(25 responses)- A88% (22)
- C8% (2)
- D4% (1)
Why each option
The ISO/IEC 27001:2013 standard includes a domain for 'Legal, statutory, regulatory and contractual requirements' but not a standalone 'Legal' domain.
ISO/IEC 27001:2013 includes a domain specifically for 'Compliance' (A.18), which covers 'Legal, statutory, regulatory and contractual requirements,' but 'Legal' itself is not a standalone domain title among the 14 main control categories specified in the standard.
'Organization of information security' (A.6) is a domain in ISO/IEC 27001:2013 covering management aspects.
'Asset management' (A.8) is a dedicated domain in ISO/IEC 27001:2013.
'Supplier relationships' (A.15) is a dedicated domain in ISO/IEC 27001:2013.
Concept tested: ISO/IEC 27001:2013 domains
Source: https://www.isms.online/iso-27001/controls/
Topics
Community Discussion
No community discussion yet for this question.