Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CIPS L4M2 Exam - Topic 3 Question 77 Discussion

Which of the following are main focuses of ISO 27001:2013 standard?1. Confidentiality2. Logistics3. Process4. Life cycle
A) 1 and 3 only
B) 3 and 4 only
C) 2 and 3 only
D) 2 and 4 only

CIPS L4M2 Exam - Topic 3 Question 77 Discussion

Actual exam question for CIPS's L4M2 exam
Question #: 77
Topic #: 3
[All L4M2 Questions]

Which of the following are main focuses of ISO 27001:2013 standard?

1. Confidentiality

2. Logistics

3. Process

4. Life cycle

Show Suggested Answer Hide Answer
Suggested Answer: A

Explanation

This International Standard (ISO 27001:2013) has been prepared to provide requirements for establishing, implementing, maintaining and continually improving an information security management system. The adoption of an information security management system is a strategic decision for an organization. The establishment and implementation of an organization's information security management system is influenced by the organization's needs and objectives, security requirements, the organizational processes used and the size and structure of the organization. All of these influencing factors are expected to change over time.

The information security management system preserves the confidentiality, integrity and availability of information by applying a risk management process and gives confidence to interested parties that risks are adequately managed.

It is important that the information security management system is part of and integrated with the organization's processes and overall management structure and that information security is considered in the design of processes, information systems, and controls. It is expected that an information security management system implementation will be scaled in accordance with the needs of the organization.

This International Standard can be used by internal and external parties to assess the organization's ability to meet the organization's own information security requirements.

The order in which requirements are presented in this International Standard does not reflect their importance or imply the order in which they are to be implemented. The list items are enumerated for reference purpose only.

ISO/IEC 27000 describes the overview and the vocabulary of information security management systems, referencing the information security management system family of standards (includ-ing ISO/IEC 27003[2], ISO/IEC 27004[3] and ISO/IEC 27005[4]), with related terms and defini-tions.


- ISO/IEC 27001:2013 Information technology --- Security techniques --- Information security management systems --- Requirements

LO 3, AC 3.1

Contribute your Thoughts:

0/2000 characters
Shantell
3 days ago
Definitely confidentiality is a big one!
upvoted 0 times
...
Jerry
8 days ago
I feel like life cycle management might be relevant, but I can't recall if it's a main focus. I guess I need to think more about what I studied!
upvoted 0 times
...
Daniel
13 days ago
I practiced a question similar to this, and I think it was about confidentiality and processes being key. So maybe A is the right choice?
upvoted 0 times
...
Katie
18 days ago
I’m not entirely sure, but I think logistics isn’t really part of ISO 27001. It seems more about processes and managing information security risks.
upvoted 0 times
...
Barney
23 days ago
I remember that ISO 27001 focuses a lot on information security, so I think confidentiality is definitely one of the main focuses.
upvoted 0 times
...

Save Cancel