Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Implementer Exam - Topic 3 Question 65 Discussion

An organization that is implementing the ISMS based on ISO/IEC 27001 has defined and communicated secure system architecture and engineering principles. However, there is no documented information related to these principles. Is this acceptable?
B) Yes, documented information related to secure system architecture and engineering principles is not directly required by the standard
A) Yes, the standard requires organizations to only communicate secure system architecture and engineering principles
C) No, documenting secure system architecture and engineering principles is required by the standard

PECB ISO-IEC-27001-Lead-Implementer Exam - Topic 3 Question 65 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Implementer exam
Question #: 65
Topic #: 3
[All ISO-IEC-27001-Lead-Implementer Questions]

An organization that is implementing the ISMS based on ISO/IEC 27001 has defined and communicated secure system architecture and engineering principles. However, there is no documented information related to these principles. Is this acceptable?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Rozella
7 hours ago
I agree, option C makes sense. Standards need documentation.
upvoted 0 times
...
Teri
5 days ago
I think it's not acceptable. Documentation is key for consistency.
upvoted 0 times
...
Maybelle
11 days ago
C) No way, they should definitely document those principles!
upvoted 0 times
...
Teresita
16 days ago
B) I think they’re covered, but it feels risky.
upvoted 0 times
...
Elke
2 months ago
C) Wait, isn't documentation crucial for compliance?
upvoted 0 times
...
Filiberto
2 months ago
B) Totally agree, documentation isn't explicitly required.
upvoted 0 times
...
Janine
2 months ago
A) Yes, communication is enough according to the standard.
upvoted 0 times
...
Antonio
3 months ago
Totally agree with B, as long as principles are communicated, it's fine.
upvoted 0 times
...
Freida
3 months ago
A is misleading, communication alone isn't enough.
upvoted 0 times
...
Avery
3 months ago
Surprised there's no documentation at all! How can they ensure compliance?
upvoted 0 times
...
Jettie
3 months ago
I disagree, C makes more sense. Documentation is key!
upvoted 0 times
...
Marjory
3 months ago
B is correct, documentation isn't explicitly required.
upvoted 0 times
...
Luisa
3 months ago
I thought the standard was flexible about documentation, but now I'm questioning if that applies to secure system architecture principles specifically.
upvoted 0 times
...
Leigha
4 months ago
I lean towards option C because I believe that having documented information is crucial for demonstrating adherence to the ISMS requirements.
upvoted 0 times
...
Tanja
4 months ago
I feel like I came across a similar question in our practice exams, and it emphasized the need for documentation to support the principles communicated.
upvoted 0 times
...
Linn
4 months ago
I think I remember that documentation is important for compliance, but I'm not entirely sure if it's explicitly required by the standard.
upvoted 0 times
...

Save Cancel