Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

APMG-International ISO-IEC-27001-Foundation Exam - Topic 8 Question 17 Discussion

What is the name of the control clause used to control information security breaches within Annex A of ISO/IEC 27001?
A) Information security event reporting
B) Information security event management
C) Response to information security events
D) Reporting information security incidents

APMG-International ISO-IEC-27001-Foundation Exam - Topic 8 Question 17 Discussion

Actual exam question for APMG-International's ISO-IEC-27001-Foundation exam
Question #: 17
Topic #: 8
[All ISO-IEC-27001-Foundation Questions]

What is the name of the control clause used to control information security breaches within Annex A of ISO/IEC 27001?

Show Suggested Answer Hide Answer
Suggested Answer: A

Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:

Annex A in ISO/IEC 27001 refers directly to ISO/IEC 27002 for control guidance. In ISO/IEC 27002:2022, Clause 6.8 is titled:

''Information security event reporting -- Information security events should be reported through appropriate management channels as quickly as possible.''

This control ensures breaches, incidents, or suspected issues are reported for action. The other options (B, C, D) are not the exact titles in Annex A. The official title is Information security event reporting, confirming Answer: A.


Contribute your Thoughts:

0/2000 characters
Johanna
10 days ago
I lean towards D) Reporting information security incidents. It covers incidents well.
upvoted 0 times
...
Lizbeth
16 days ago
I feel like it's A) Information security event reporting. More straightforward.
upvoted 0 times
...
Aleta
21 days ago
I think it's C) Response to information security events. Sounds right.
upvoted 0 times
...
Cammy
26 days ago
Just to clarify, it's definitely about managing events, not just reporting.
upvoted 0 times
...
Toshia
1 month ago
Wait, are we sure about that? Seems a bit off.
upvoted 0 times
...
Hayley
1 month ago
Totally agree with C! That's the right one.
upvoted 0 times
...
Stanford
1 month ago
I thought it was D) Reporting information security incidents!
upvoted 0 times
...
Jonell
2 months ago
It's C) Response to information security events.
upvoted 0 times
...
Bette
2 months ago
I thought it was A, but now I'm second-guessing myself. I need to remember the exact wording from the standard!
upvoted 0 times
...
Jerry
2 months ago
I feel like the answer might be D, but I can't recall if it was specifically about reporting incidents or just general event management.
upvoted 0 times
...
Francine
2 months ago
I remember practicing a question similar to this, and I think it was about incident management. Could it be B or C?
upvoted 0 times
...
Kati
2 months ago
I think the control clause is related to how we manage security events, but I'm not sure if it's specifically about reporting or response.
upvoted 0 times
...

Save Cancel