Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27002-Foundation Exam - Topic 1 Question 5 Discussion

What does ISO/IEC 27002 provide?
A) Guidance for the implementation of information security controls
B) Requirements for the implementation of information security controls
C) Guidance for the management of information security risks

PECB ISO-IEC-27002-Foundation Exam - Topic 1 Question 5 Discussion

Actual exam question for PECB's ISO-IEC-27002-Foundation exam
Question #: 5
Topic #: 1
[All ISO-IEC-27002-Foundation Questions]

What does ISO/IEC 27002 provide?

Show Suggested Answer Hide Answer
Suggested Answer: A

ISO/IEC 27002:2022 provides guidance for selecting, implementing, and managing information security controls. It is not the certification requirements standard; that role belongs to ISO/IEC 27001. ISO/IEC 27002 supports organizations by explaining the purpose of each control, the implementation guidance, and other related information needed to apply controls appropriately. Its controls are grouped into organizational, people, physical, and technological themes. The standard is intended to be used as a reference when organizations design security measures based on their risks, business needs, legal obligations, contractual requirements, and information security objectives. Therefore, option A is correct because ''guidance'' is the core function of ISO/IEC 27002. Option B is incorrect because ISO/IEC 27002 does not set mandatory requirements for certification. Option C is related to risk management, but it is not the main purpose of ISO/IEC 27002; risk management guidance is more directly associated with ISO/IEC 27005. ISO/IEC 27002 guides control implementation after risk and control needs are determined. Reference/Chapters: ISO/IEC 27002:2022, Clause 1 Scope; Clause 4 Structure of the standard; Controls 5--8.


Contribute your Thoughts:

0/2000 characters
Magda
7 hours ago
It provides guidance for implementing security controls!
upvoted 0 times
...
Mitzie
5 days ago
I believe it focuses on guidance for information security controls, but I might mix it up with another standard that deals with risk management.
upvoted 0 times
...
Karina
11 days ago
I’m a bit confused; I thought it was more about requirements rather than just guidance. I need to double-check my notes.
upvoted 0 times
...
Ernest
16 days ago
I remember studying that ISO/IEC 27002 provides guidance, not requirements. It’s similar to that practice question we did last week.
upvoted 0 times
...
Georgiana
2 months ago
I think ISO/IEC 27002 is about guidance for implementing controls, but I’m not completely sure if it also covers risk management.
upvoted 0 times
...

Save Cancel