nerdexam
(ISC)2

CSSLP · Question #322

ISO 27003 is an information security standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Which of the following elem

The correct answer is A. Inter-Organization Co-operation C. CSFs (Critical success factors) E. Terms and Definitions F. Guidance on process approach. ISO 27003, an information security standard, provides guidance for implementing an Information Security Management System (ISMS) and includes elements like Critical Success Factors, Inter-Organization Co-operation, guidance on process approach, and Terms and Definitions.

Secure Software Lifecycle Management

Question

ISO 27003 is an information security standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Which of the following elements does this standard contain? Each correct answer represents a complete solution. Choose all that apply.

Options

  • AInter-Organization Co-operation
  • BInformation Security Risk Treatment
  • CCSFs (Critical success factors)
  • DSystem requirements for certification bodies Management
  • ETerms and Definitions
  • FGuidance on process approach

How the community answered

(27 responses)
  • A
    93% (25)
  • B
    4% (1)
  • D
    4% (1)

Why each option

ISO 27003, an information security standard, provides guidance for implementing an Information Security Management System (ISMS) and includes elements like Critical Success Factors, Inter-Organization Co-operation, guidance on process approach, and Terms and Definitions.

AInter-Organization Co-operationCorrect

ISO 27003 provides guidance on various aspects of ISMS implementation, which includes considerations for inter-organization cooperation in information security.

BInformation Security Risk Treatment

While ISO 27003 provides guidance on implementing the risk treatment process, 'Information Security Risk Treatment' itself is a core process of ISO 27001, and 27003 details how to achieve it, not an element in the same way as the other options.

CCSFs (Critical success factors)Correct

Critical Success Factors (CSFs) are a recognized component within ISO 27003, highlighting key elements for effective ISMS implementation.

DSystem requirements for certification bodies Management

System requirements for certification bodies Management are typically addressed by standards such as ISO 27006, not ISO 27003, which focuses on ISMS implementation guidance for organizations.

ETerms and DefinitionsCorrect

Like many standards, ISO 27003 includes or references a section on Terms and Definitions to ensure consistent understanding of concepts.

FGuidance on process approachCorrect

ISO 27003 emphasizes and provides guidance on adopting a process approach for managing an Information Security Management System (ISMS).

Concept tested: ISO 27003 standard elements

Topics

#ISO 27003#ISMS Implementation#Information Security Standards#Critical Success Factors

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice