PECB
LEAD-IMPLEMENTER · Question #21
LEAD-IMPLEMENTER Question #21: Real Exam Question with Answer & Explanation
The correct answer is C. Yes, but documenting each security control and not the process in general will make it difficult to. See the full explanation below for the reasoning.
Question
An organization documented each security control that it Implemented by describing their functions in detail. Is this compliant with ISO/IEC 27001?
Options
- ANo, the standard requires to document only the operation of processes and controls, so no
- BNo, because the documented information should have a strict format, including the date, version
- CYes, but documenting each security control and not the process in general will make it difficult to
Community Discussion
No community discussion yet for this question.