nerdexam
(ISC)2

CSSLP · Question #137

Which of the following sections come under the ISO/IEC 27002 standard?

The correct answer is A. Security policy B. Asset management D. Risk assessment. ISO/IEC 27002 provides a set of generic information security controls, including sections on Security policy, Asset management, and Risk assessment. These sections guide organizations in implementing effective information security management.

Secure Software Lifecycle Management

Question

Which of the following sections come under the ISO/IEC 27002 standard?

Options

  • ASecurity policy
  • BAsset management
  • CFinancial assessment
  • DRisk assessment

How the community answered

(23 responses)
  • A
    91% (21)
  • C
    9% (2)

Why each option

ISO/IEC 27002 provides a set of generic information security controls, including sections on Security policy, Asset management, and Risk assessment. These sections guide organizations in implementing effective information security management.

ASecurity policyCorrect

Security policy is a key clause (e.g., Clause 5.1 in ISO 27002:2022) in ISO/IEC 27002, which provides guidance on establishing, reviewing, and maintaining an organization's information security policies.

BAsset managementCorrect

Asset management is a dedicated section (e.g., Clause 5.9-5.14 in ISO 27002:2022) in ISO/IEC 27002, covering the identification, classification, ownership, and protection of information assets.

CFinancial assessment

Financial assessment is not a direct section or control family within the ISO/IEC 27002 standard; its focus is on information security controls, not financial evaluation.

DRisk assessmentCorrect

Risk assessment is a fundamental part of establishing an Information Security Management System (ISMS) according to ISO/IEC 27001, and ISO/IEC 27002 provides guidance for controls related to risk management, implicitly covering risk assessment as part of the overall process.

Concept tested: ISO/IEC 27002 control categories

Source: https://www.iso.org/standard/72138.html

Topics

#ISO/IEC 27002#Information Security Controls#Security Policy#Asset Management

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice