ITSM20F · Question #87
What is a shared concept of both ISO/IEC 27001 and ISCWIEC 20000?
The correct answer is C. Information security management. Information security management is the only concept explicitly required by both standards: ISO/IEC 27001 defines the entire framework for an Information Security Management System (ISMS), while ISO/IEC 20000 (IT Service Management) includes information security management as…
Question
What is a shared concept of both ISO/IEC 27001 and ISCWIEC 20000?
Options
- ACapacity management
- BIncident management
- CInformation security management
- DRelease management
How the community answered
(23 responses)- A4% (1)
- C87% (20)
- D9% (2)
Explanation
Information security management is the only concept explicitly required by both standards: ISO/IEC 27001 defines the entire framework for an Information Security Management System (ISMS), while ISO/IEC 20000 (IT Service Management) includes information security management as one of its mandatory service management processes - recognizing that secure IT services depend on formal security controls.
Why the distractors are wrong:
- A (Capacity management) and D (Release management) are ITIL-derived processes that appear in ISO/IEC 20000 but have no equivalent requirement in ISO/IEC 27001, which focuses on protecting information assets rather than managing service delivery mechanics.
- B (Incident management) is tricky - ISO/IEC 27001 addresses security incident management specifically (Annex A control), but "incident management" as a broader IT service process belongs to ISO/IEC 20000; they don't share the concept at the same scope.
Memory tip: Think "27001 = Security first, security always." When ISO/IEC 20000 (service management) needs to overlap with 27001, it must borrow 27001's home turf - information security - making C the natural shared ground between the two standards.
Topics
Community Discussion
No community discussion yet for this question.