CCSP · Question #838
Which of the following best describes the purpose and scope of ISO/IEC 27034-1?
The correct answer is D. Provides an overview of application security that introduces definitive concepts, principles, and. The question asks to identify the primary focus and scope of the ISO/IEC 27034-1 standard.
Question
Which of the following best describes the purpose and scope of ISO/IEC 27034-1?
Options
- ADescribes international privacy standards for cloud computing
- BServes as a newer replacement for NIST 800-52 r4
- CProvides on overview of network and infrastructure security designed to secure cloud
- DProvides an overview of application security that introduces definitive concepts, principles, and
How the community answered
(60 responses)- A3% (2)
- B2% (1)
- D95% (57)
Why each option
The question asks to identify the primary focus and scope of the ISO/IEC 27034-1 standard.
ISO/IEC 27034-1 does not primarily describe international privacy standards for cloud computing; other standards like ISO/IEC 27017 or 27018 address those areas.
ISO/IEC 27034-1 is an international standard focused on application security, unrelated to NIST 800-52 r4 which is a NIST publication on guidance for cloud computing security.
While application security is part of overall IT security, ISO/IEC 27034-1 does not primarily provide an overview of network and infrastructure security; its scope is specifically application security.
D is correct because ISO/IEC 27034-1 specifically focuses on application security, providing an overview of concepts, principles, and processes for integrating security into the application lifecycle. It aims to ensure information security throughout the software development process.
Concept tested: ISO/IEC 27034-1 application security overview
Source: https://www.iso.org/standard/45170.html
Topics
Community Discussion
No community discussion yet for this question.