Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Implementer Exam - Topic 1 Question 74 Discussion

An organization has adopted a new authentication method to ensure secure access to sensitive areas and facilities of the company. It requires every employee to use a two-factor authentication (password and QR code). This control has been documented, standardized, and communicated to all employees, however its use has been "left to individual initiative, and it is likely that failures can be detected. Which level of maturity does this control refer to?
B) Defined
A) Optimized
C) Quantitatively managed

PECB ISO-IEC-27001-Lead-Implementer Exam - Topic 1 Question 74 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Implementer exam
Question #: 74
Topic #: 1
[All ISO-IEC-27001-Lead-Implementer Questions]

An organization has adopted a new authentication method to ensure secure access to sensitive areas and facilities of the company. It requires every employee to use a two-factor authentication (password and QR code). This control has been documented, standardized, and communicated to all employees, however its use has been "left to individual initiative, and it is likely that failures can be detected. Which level of maturity does this control refer to?

Show Suggested Answer Hide Answer
Suggested Answer: B

According to the ISO/IEC 27001:2022 Lead Implementer objectives and content, the maturity levels of information security controls are based on the ISO/IEC 15504 standard, which defines five levels of process capability: incomplete, performed, managed, established, and optimized1. Each level has a set of attributes that describe the characteristics of the process at that level.The level of defined corresponds to the attribute of process performance, which means that the process achieves its expected outcomes2. In this case, the control of two-factor authentication has been documented, standardized, and communicated, which implies that it has a clear purpose and expected outcomes. However, the control is not consistently implemented, monitored, or measured, which means that it does not meet the attributes of the higher levels of managed, established, or optimized. Therefore, the control is at the level of defined, which is the second level of maturity.

1: ISO/IEC 27001:2022 Lead Implementer Course Brochure, page 5

2: ISO/IEC 27001:2022 Lead Implementer Course Presentation, slide 25


Contribute your Thoughts:

0/2000 characters
Ciara
4 days ago
I feel like this is definitely not Optimized since it’s left to individual initiative. It seems more like Defined, but I’m a bit confused about the implications of that.
upvoted 0 times
...
Yvonne
9 days ago
I remember a practice question about maturity levels, and it seems like this could be Quantitatively managed because they mention detecting failures, but I could be mixing it up.
upvoted 0 times
...
Alishia
14 days ago
I think this might be the Defined level since the control is documented and standardized, but I'm not entirely sure about the individual initiative part.
upvoted 0 times
...

Save Cancel