Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27002-Foundation Exam - Topic 1 Question 5 Discussion

Actual exam question for PECB's ISO-IEC-27002-Foundation exam
Question #: 5
Topic #: 1
[All ISO-IEC-27002-Foundation Questions]

What does ISO/IEC 27002 provide?

Show Suggested Answer Hide Answer
Suggested Answer: A

ISO/IEC 27002:2022 provides guidance for selecting, implementing, and managing information security controls. It is not the certification requirements standard; that role belongs to ISO/IEC 27001. ISO/IEC 27002 supports organizations by explaining the purpose of each control, the implementation guidance, and other related information needed to apply controls appropriately. Its controls are grouped into organizational, people, physical, and technological themes. The standard is intended to be used as a reference when organizations design security measures based on their risks, business needs, legal obligations, contractual requirements, and information security objectives. Therefore, option A is correct because ''guidance'' is the core function of ISO/IEC 27002. Option B is incorrect because ISO/IEC 27002 does not set mandatory requirements for certification. Option C is related to risk management, but it is not the main purpose of ISO/IEC 27002; risk management guidance is more directly associated with ISO/IEC 27005. ISO/IEC 27002 guides control implementation after risk and control needs are determined. Reference/Chapters: ISO/IEC 27002:2022, Clause 1 Scope; Clause 4 Structure of the standard; Controls 5--8.


Contribute your Thoughts:

0/2000 characters
Georgiana
16 days ago
I think ISO/IEC 27002 is about guidance for implementing controls, but I’m not completely sure if it also covers risk management.
upvoted 0 times
...

Save Cancel