LEAD-AUDITOR · Question #174
LEAD-AUDITOR Question #174: Real Exam Question with Answer & Explanation
The correct answer is C. Yes, the implementation of the new control should be justified and included in the SoA. The Statement of Applicability (SoA) is a core document within an ISMS that outlines the security controls an organization implements. When a new control, such as the SSH protocol, is implemented, it should be included in the SoA to reflect the current state of the ISMS. The SoA
Question
Options
- ANo, the usage of SSH protocol is not an ISO/IEC 27001 requirement and; therefore, does not need
- BNo, because the SoA should be updated only when new controls are added, not when old ones
- CYes, the implementation of the new control should be justified and included in the SoA
Explanation
The Statement of Applicability (SoA) is a core document within an ISMS that outlines the security controls an organization implements. When a new control, such as the SSH protocol, is implemented, it should be included in the SoA to reflect the current state of the ISMS. The SoA should be updated to justify the inclusion of the new control and to document how it is implemented within the organization.
Community Discussion
No community discussion yet for this question.