CSSLP · Question #131
Numerous information security standards promote good security practices and define frameworks or systems to structure the analysis and design for managing information security controls. Which of the f
The correct answer is B. Human resources security C. Organization of information security D. Risk assessment and treatment. International information security standards, such as ISO/IEC 27002, include clauses covering Human resources security, Organization of information security, and Risk assessment and treatment. These areas specify best practices for managing information security controls.
Question
Numerous information security standards promote good security practices and define frameworks or systems to structure the analysis and design for managing information security controls. Which of the following are the international information security standards? Each correct answer represents a complete solution. Choose all that apply.
Options
- AAU audit and accountability
- BHuman resources security
- COrganization of information security
- DRisk assessment and treatment
How the community answered
(16 responses)- A6% (1)
- B94% (15)
Why each option
International information security standards, such as ISO/IEC 27002, include clauses covering Human resources security, Organization of information security, and Risk assessment and treatment. These areas specify best practices for managing information security controls.
"AU audit and accountability" sounds like a NIST SP 800-53 control family, which is a US federal standard, not an international information security standard in the same context as ISO/IEC 27002 sections.
Human resources security is a domain within international information security standards like ISO/IEC 27002, addressing security aspects related to employees, contractors, and third-party users.
Organization of information security is a core clause in international standards such as ISO/IEC 27002, covering the internal organization of information security governance and responsibilities.
Risk assessment and treatment are fundamental processes and clauses found in international standards like ISO/IEC 27001 (which defines the ISMS) and ISO/IEC 27002 (which provides guidance on controls), essential for managing information security.
Concept tested: International information security standards (ISO/IEC 27002)
Source: https://www.iso.org/standard/72138.html
Topics
Community Discussion
No community discussion yet for this question.