nerdexam
PECB

LEAD-AUDITOR · Question #255

Which controls are related to the Annex A controls of ISO/IEC 27001 and are often selected from other guides and standards or defined by the organization to meet its specific needs?

The correct answer is C. Specific controls. Specific controls are tailored security controls chosen based on risk assessments, industry best practices, and regulatory requirements. These align with ISO/IEC 27001:2022 Annex A controls, which organizations select based on their risk landscape. General controls refer to broad

Information Security Controls

Question

Which controls are related to the Annex A controls of ISO/IEC 27001 and are often selected from other guides and standards or defined by the organization to meet its specific needs?

Options

  • AGeneral controls
  • BStrategic controls
  • CSpecific controls

How the community answered

(23 responses)
  • A
    9% (2)
  • B
    4% (1)
  • C
    87% (20)

Explanation

Specific controls are tailored security controls chosen based on risk assessments, industry best practices, and regulatory requirements. These align with ISO/IEC 27001:2022 Annex A controls, which organizations select based on their risk landscape. General controls refer to broad security measures that apply to all organizations. Strategic controls focus on high-level governance and long-term security goals, not detailed security implementations.

Topics

#specific controls#Annex A#ISO/IEC 27001#control selection

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice