nerdexam
(ISC)2

CSSLP · Question #233

Which of the following ISO standards is entitled as "Information technology - Security techniques - Information security management - Measurement"?

The correct answer is C. ISO 27004. The ISO 27004 standard is specifically titled "Information technology - Security techniques - Information security management - Measurement," focusing on the metrics and methods for measuring the effectiveness of an Information Security Management System (ISMS). This standard…

Secure Software Lifecycle Management

Question

Which of the following ISO standards is entitled as "Information technology - Security techniques

  • Information security management - Measurement"?

Options

  • AISO 27003
  • BISO 27005
  • CISO 27004
  • DISO 27006

How the community answered

(46 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    91% (42)
  • D
    2% (1)

Why each option

The ISO 27004 standard is specifically titled "Information technology - Security techniques - Information security management - Measurement," focusing on the metrics and methods for measuring the effectiveness of an Information Security Management System (ISMS). This standard provides guidance on developing and implementing information security measurements and metrics.

AISO 27003

ISO/IEC 27003 provides guidance on the implementation of an Information Security Management System (ISMS), rather than focusing on measurement.

BISO 27005

ISO/IEC 27005 provides guidelines for information security risk management, not information security measurement.

CISO 27004Correct

ISO/IEC 27004 is indeed the international standard that provides guidance on information security measurement, focusing on how to develop and use metrics and indicators to evaluate the performance of an Information Security Management System (ISMS). Its full title is "Information technology - Security techniques - Information security management - Measurement," directly matching the question's description. This standard helps organizations measure the effectiveness of their security controls and management processes.

DISO 27006

ISO/IEC 27006 provides requirements for bodies providing audit and certification of Information Security Management Systems (ISMS), focusing on certification body accreditation, not measurement itself.

Concept tested: ISO 27000 series standards

Source: https://www.iso.org/standard/75336.html

Topics

#ISO standards#Information security management#Security measurement#ISO 27004

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice