GSLC · Question #92
Which of the following sections come under the ISO/IEC 27002 standard?
The correct answer is B. Security policy C. Risk assessment D. Asset management. ISO/IEC 27002 is an information security controls standard that includes security policy, risk assessment, and asset management as defined control domains. Financial assessment is not part of this standard.
Question
Which of the following sections come under the ISO/IEC 27002 standard?
Options
- AFinancial assessment
- BSecurity policy
- CRisk assessment
- DAsset management
How the community answered
(22 responses)- A5% (1)
- B95% (21)
Why each option
ISO/IEC 27002 is an information security controls standard that includes security policy, risk assessment, and asset management as defined control domains. Financial assessment is not part of this standard.
Financial assessment is not a section or control domain within ISO/IEC 27002 - the standard addresses information security controls exclusively, not financial evaluation or accounting processes.
Security policy is a defined section in ISO/IEC 27002 (Section 5) that addresses management direction for information security through documented policies and supporting review processes.
Risk assessment is covered within ISO/IEC 27002 as part of its information security risk management guidance, providing controls to help organizations identify and evaluate information security risks.
Asset management is an explicit section in ISO/IEC 27002 (Section 8) that governs responsibility for organizational assets and the classification of information.
Concept tested: ISO/IEC 27002 information security standard control domains
Source: https://www.iso.org/standard/75652.html
Topics
Community Discussion
No community discussion yet for this question.