PECB
LEAD-IMPLEMENTER · Question #232
Which control in Annex A of ISO/IEC 27001 requires that the information security requirements shall be identified, specified, and approved when developing or acquiring applications?
The correct answer is B. A.8.26 Application security requirements. See the full explanation below for the reasoning.
Question
Which control in Annex A of ISO/IEC 27001 requires that the information security requirements shall be identified, specified, and approved when developing or acquiring applications?
Options
- AA.8.25 Secure development life cycle
- BA.8.26 Application security requirements
- CA.8.27 Secure system architecture and engineering principles
How the community answered
(24 responses)- A13% (3)
- B83% (20)
- C4% (1)
Community Discussion
No community discussion yet for this question.