Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

APMG-International ISO-IEC-27001-Foundation Exam - Topic 5 Question 18 Discussion

What is required to be reported by the Information security event reporting control?
D) Observed or suspected events
A) Information disclosure
B) Unauthorized access
C) Asset disposal

APMG-International ISO-IEC-27001-Foundation Exam - Topic 5 Question 18 Discussion

Actual exam question for APMG-International's ISO-IEC-27001-Foundation exam
Question #: 18
Topic #: 5
[All ISO-IEC-27001-Foundation Questions]

What is required to be reported by the Information security event reporting control?

Show Suggested Answer Hide Answer
Suggested Answer: D

Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:

Annex A, control 6.8 (Information security event reporting) specifies:

''Information security events should be reported through appropriate management channels as quickly as possible. The organization should require all employees and contractors to note and report any observed or suspected information security events.''

This wording confirms that the required reporting covers ''observed or suspected events.'' Specific event types like information disclosure (A) or unauthorized access (B) are examples but not the broad requirement. Asset disposal (C) is addressed separately under equipment lifecycle controls (Annex A.7.14).

Therefore, the verified correct answer is D: Observed or suspected events.


Contribute your Thoughts:

0/2000 characters
Barabara
4 hours ago
C seems less relevant in this context.
upvoted 0 times
...
Gail
5 days ago
B is definitely a must-report. Unauthorized access can be serious.
upvoted 0 times
...
Marguerita
10 days ago
A is important too, but not as much as D.
upvoted 0 times
...
Merissa
16 days ago
I agree, observed or suspected events are crucial.
upvoted 0 times
...
Florinda
21 days ago
I think D is the best choice.
upvoted 0 times
...
Wynell
26 days ago
Not sure if all of these are necessary to report.
upvoted 0 times
...
Selma
1 month ago
Yeah, observed or suspected events should be reported for sure.
upvoted 0 times
...
Shawana
1 month ago
Surprised that information disclosure isn't the top priority!
upvoted 0 times
...
Fatima
1 month ago
I think asset disposal is also important.
upvoted 0 times
...
Patrick
2 months ago
Definitely includes unauthorized access!
upvoted 0 times
...
Iluminada
2 months ago
I’m leaning towards option D, but I vaguely remember something about information disclosure being important too.
upvoted 0 times
...
Doyle
2 months ago
I feel like asset disposal might be relevant, but it seems more like a separate issue compared to the other options.
upvoted 0 times
...
In
2 months ago
I remember practicing a question about unauthorized access being a key reporting requirement, but I can't recall if that's the main focus here.
upvoted 0 times
...
Ezekiel
2 months ago
I think the reporting control focuses on observed or suspected events, but I'm not entirely sure if that's the only thing we need to report.
upvoted 0 times
...

Save Cancel