nerdexam
(ISC)2

CGRC · Question #477

ISO 17799 has two parts. The first part is an implementation guide with guidelines on how to build a comprehensive information security infrastructure and the second part is an auditing guide based on

The correct answer is A. Information security policy for the organization B. Personnel security C. Business continuity management E. System development and maintenance. ISO 17799 (now largely incorporated into ISO 27002) includes key domains such as Information security policy, Personnel security, Business continuity management, and System development and maintenance.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

ISO 17799 has two parts. The first part is an implementation guide with guidelines on how to build a comprehensive information security infrastructure and the second part is an auditing guide based on requirements that must be met for an organization to be deemed compliant with ISO 17799. 4 What are the ISO 17799 domains? Each correct answer represents a complete solution. Choose all that apply. Response:

Options

  • AInformation security policy for the organization
  • BPersonnel security
  • CBusiness continuity management
  • DSystem architecture management
  • ESystem development and maintenance

How the community answered

(20 responses)
  • A
    90% (18)
  • D
    10% (2)

Why each option

ISO 17799 (now largely incorporated into ISO 27002) includes key domains such as Information security policy, Personnel security, Business continuity management, and System development and maintenance.

AInformation security policy for the organizationCorrect

Information security policy for the organization is a fundamental domain in ISO 17799/27002, establishing management direction for information security.

BPersonnel securityCorrect

Personnel security addresses human resources security aspects, including background checks, roles, and responsibilities, which are critical for an organization's security posture.

CBusiness continuity managementCorrect

Business continuity management focuses on maintaining operations during and after disruptive events to ensure continuous service availability.

DSystem architecture management

System architecture management is not explicitly listed as one of the primary high-level control domains in ISO 17799 (ISO 27002), although aspects of architecture would be covered within other domains like system acquisition, development and maintenance.

ESystem development and maintenanceCorrect

System development and maintenance ensures that security is integrated throughout the lifecycle of information systems, from design to disposal.

Concept tested: ISO 17799/27002 control domains

Source: en.wikipedia.org/wiki/ISO/IEC_27002

Topics

#ISO 17799#Information Security Domains#Information Security Policy#Business Continuity Management

Community Discussion

No community discussion yet for this question.

Full CGRC Practice