nerdexam
EXIN

ITSM20F · Question #55

What is a shared concept of both ISO/IEC 27001 and ISO/IEC 20000?

The correct answer is C. Information Security Management. Information Security Management is the bridge between these two standards: ISO/IEC 27001 is dedicated entirely to establishing an Information Security Management System (ISMS), while ISO/IEC 20000 (IT Service Management) explicitly includes information security management as a…

Service Management System (SMS)

Question

What is a shared concept of both ISO/IEC 27001 and ISO/IEC 20000?

Options

  • ACapacity Management
  • BIncident Management
  • CInformation Security Management
  • DRelease Management

How the community answered

(43 responses)
  • A
    14% (6)
  • B
    5% (2)
  • C
    74% (32)
  • D
    7% (3)

Explanation

Information Security Management is the bridge between these two standards: ISO/IEC 27001 is dedicated entirely to establishing an Information Security Management System (ISMS), while ISO/IEC 20000 (IT Service Management) explicitly includes information security management as a required component of delivering secure IT services. Both standards mandate that organizations define, implement, and continually improve controls around information security, making it their clearest shared concept.

Why the distractors are wrong:

  • A. Capacity Management - belongs to ISO 20000's service delivery processes; ISO 27001 has no equivalent process.
  • B. Incident Management - while ISO 27001 addresses security incident management, "Incident Management" as a formal process discipline is native to ISO 20000 (ITSM), not a shared framework concept.
  • D. Release Management - exclusively an ISO 20000 (ITSM) concern; it has no counterpart in ISO 27001.

Memory tip: Anchor on "27001 = Security." Since ISO 20000 governs IT services and those services must be secure, it borrows the Information Security Management concept directly from 27001's domain - that overlap is the answer whenever both standards appear in the same question.

Topics

#ISO/IEC 27001#ISO/IEC 20000#Information Security Management#standards alignment

Community Discussion

No community discussion yet for this question.

Full ITSM20F Practice