Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CertiProf I27001F Exam - Topic 2 Question 10 Discussion

Which statement describes the difference between ISO/IEC 27001:2022 and ISO/IEC 27002:2022?
C) ISO/IEC 27001:2022 contains mandatory requirements, while ISO/IEC 27002:2022 provides guidance on information security controls
A) ISO/IEC 27002:2022 provides guidance on measurement, and ISO/IEC 27001:2022 provides guidance on information security controls
B) ISO/IEC 27002:2022 provides mandatory requirements for a risk management approach, and ISO/IEC 27001:2022 contains mandatory requirements for an ISMS
D) ISO/IEC 27002:2022 contains mandatory requirements, while ISO/IEC 27001:2022 provides guidance on information security controls

CertiProf I27001F Exam - Topic 2 Question 10 Discussion

Actual exam question for CertiProf's I27001F exam
Question #: 10
Topic #: 2
[All I27001F Questions]

Which statement describes the difference between ISO/IEC 27001:2022 and ISO/IEC 27002:2022?

Show Suggested Answer Hide Answer
Suggested Answer: C

ISO/IEC 27001:2022 is the certifiable standard that contains requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System. ISO/IEC 27002:2022 is not a certifiable requirements standard. It provides guidance for selecting, implementing, and managing information security controls, including the controls referenced in Annex A of ISO/IEC 27001:2022. Therefore, option C is correct.

=======


Contribute your Thoughts:

0/2000 characters
Verlene
16 hours ago
No way, A is misleading. C is clearer.
upvoted 0 times
...
Maurine
6 days ago
I lean towards A. Measurement is key in 27002.
upvoted 0 times
...
Reid
11 days ago
C makes sense. 27001 is the framework.
upvoted 0 times
...
Dick
16 days ago
I feel confused about the differences.
upvoted 0 times
...
Tracie
21 days ago
Agreed! 27002 is more about guidance.
upvoted 0 times
...
Ruthann
26 days ago
I think C is correct. 27001 has mandatory requirements.
upvoted 0 times
...
Truman
1 month ago
Just to clarify, 27002 is more about guidance, right?
upvoted 0 times
...
Lashawn
1 month ago
A is misleading, 27001 is definitely about ISMS.
upvoted 0 times
...
Ria
1 month ago
Wait, are we sure about that? I thought 27002 had more requirements.
upvoted 0 times
...
Carlton
2 months ago
Totally agree with C, makes sense!
upvoted 0 times
...
Jennie
2 months ago
C is correct! 27001 has the mandatory stuff.
upvoted 0 times
...
Daniela
2 months ago
I’m confused about the specifics, but I remember something about 27002 providing guidance. I just can’t recall if it’s mandatory or not. Maybe A or C?
upvoted 0 times
...
Carin
2 months ago
I practiced a question similar to this, and I think it was clear that 27001 is the one with the mandatory requirements. So, I’m leaning towards C as well.
upvoted 0 times
...
Loise
2 months ago
I'm not entirely sure, but I feel like 27002 is more about controls and best practices, not mandatory requirements. Could it be A?
upvoted 0 times
...
Evangelina
2 months ago
I think I remember that ISO/IEC 27001:2022 has the mandatory requirements for an ISMS, while 27002:2022 is more about guidance. So, maybe C?
upvoted 0 times
...

Save Cancel