Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CompTIA CY0-001 Exam - Topic 4 Question 5 Discussion

Which of the following International Organization for Standardization (ISO) standards should be selected for certification to use for third-party assurance for responsible AI practices?
D) 42001
A) 20000
B) 27001
C) 27701

CompTIA CY0-001 Exam - Topic 4 Question 5 Discussion

Actual exam question for CompTIA's CY0-001 exam
Question #: 5
Topic #: 4
[All CY0-001 Questions]

Which of the following International Organization for Standardization (ISO) standards should be selected for certification to use for third-party assurance for responsible AI practices?

Show Suggested Answer Hide Answer
Suggested Answer: D

Basic Concept: ISO develops international standards for management systems across various domains. For organizations seeking third-party certification demonstrating commitment to responsible AI governance practices, the appropriate ISO standard must specifically address AI management systems. CompTIA SecAI+ Exam Objectives cover ISO standards relevant to AI governance under Domain 4.

Why D is Correct: ISO 42001 is the International Standard for Artificial Intelligence Management Systems (AIMS). It provides a framework for establishing, implementing, maintaining, and continually improving an AI management system within organizations. ISO 42001 certification provides third-party assurance specifically for responsible AI practices including risk management, transparency, human oversight, and ethical AI governance --- directly answering the question.

Why A is Wrong: ISO 20000 is the standard for IT Service Management (ITSM). It provides requirements for establishing and maintaining a service management system for IT services. It does not address AI governance or responsible AI practices.

Why B is Wrong: ISO 27001 is the standard for Information Security Management Systems (ISMS). It addresses general information security risk management, not AI-specific governance or responsible AI practices such as fairness, transparency, and AI lifecycle management.

Why C is Wrong: ISO 27701 extends ISO 27001 to address Privacy Information Management (PIMS), covering personal data protection requirements aligned with GDPR. While relevant to data privacy in AI systems, it does not specifically certify responsible AI governance practices.


Contribute your Thoughts:

0/2000 characters
Dortha
3 hours ago
I practiced a question similar to this, and I think ISO 27701 was highlighted for AI ethics, but I could be mixing it up with another standard.
upvoted 0 times
...
Tijuana
5 days ago
I feel like ISO 42001 could be relevant too, but I can't recall what it specifically covers.
upvoted 0 times
...
Louvenia
10 days ago
I'm not entirely sure, but I remember ISO 27001 is about information security. Could that relate to AI practices?
upvoted 0 times
...
Luisa
16 days ago
I think it might be ISO 27701 since it deals with privacy and data protection, which are crucial for responsible AI.
upvoted 0 times
...

Save Cancel