Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CertiProf I27001F Exam - Topic 2 Question 10 Discussion

Which statement describes the difference between ISO/IEC 27001:2022 and ISO/IEC 27002:2022?
C) ISO/IEC 27001:2022 contains mandatory requirements, while ISO/IEC 27002:2022 provides guidance on information security controls
A) ISO/IEC 27002:2022 provides guidance on measurement, and ISO/IEC 27001:2022 provides guidance on information security controls
B) ISO/IEC 27002:2022 provides mandatory requirements for a risk management approach, and ISO/IEC 27001:2022 contains mandatory requirements for an ISMS
D) ISO/IEC 27002:2022 contains mandatory requirements, while ISO/IEC 27001:2022 provides guidance on information security controls

CertiProf I27001F Exam - Topic 2 Question 10 Discussion

Actual exam question for CertiProf's I27001F exam
Question #: 10
Topic #: 2
[All I27001F Questions]

Which statement describes the difference between ISO/IEC 27001:2022 and ISO/IEC 27002:2022?

Show Suggested Answer Hide Answer
Suggested Answer: C

ISO/IEC 27001:2022 is the certifiable standard that contains requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System. ISO/IEC 27002:2022 is not a certifiable requirements standard. It provides guidance for selecting, implementing, and managing information security controls, including the controls referenced in Annex A of ISO/IEC 27001:2022. Therefore, option C is correct.

=======


Contribute your Thoughts:

0/2000 characters
Carlton
2 days ago
Totally agree with C, makes sense!
upvoted 0 times
...
Jennie
7 days ago
C is correct! 27001 has the mandatory stuff.
upvoted 0 times
...
Daniela
12 days ago
I’m confused about the specifics, but I remember something about 27002 providing guidance. I just can’t recall if it’s mandatory or not. Maybe A or C?
upvoted 0 times
...
Carin
18 days ago
I practiced a question similar to this, and I think it was clear that 27001 is the one with the mandatory requirements. So, I’m leaning towards C as well.
upvoted 0 times
...
Loise
23 days ago
I'm not entirely sure, but I feel like 27002 is more about controls and best practices, not mandatory requirements. Could it be A?
upvoted 0 times
...
Evangelina
28 days ago
I think I remember that ISO/IEC 27001:2022 has the mandatory requirements for an ISMS, while 27002:2022 is more about guidance. So, maybe C?
upvoted 0 times
...

Save Cancel