Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27002-Foundation Exam - Topic 2 Question 3 Discussion

Which of the following controls should the organization implement to ensure that its approach to managing information security continues to be suitable, adequate and effective?
B) Control 5.35 Independent review of information security
A) Control 5.4 Management responsibilities
C) Control 5.24 Information security incident management planning and preparation

PECB ISO-IEC-27002-Foundation Exam - Topic 2 Question 3 Discussion

Actual exam question for PECB's ISO-IEC-27002-Foundation exam
Question #: 3
Topic #: 2
[All ISO-IEC-27002-Foundation Questions]

Which of the following controls should the organization implement to ensure that its approach to managing information security continues to be suitable, adequate and effective?

Show Suggested Answer Hide Answer
Suggested Answer: B

Control 5.35, Independent review of information security, is the control intended to ensure that the organization's approach to managing information security remains suitable, adequate, and effective. Independent reviews provide objective evaluation of whether policies, processes, controls, responsibilities, and implementation remain aligned with business needs, risks, legal requirements, and the organization's security objectives. The review may consider governance, control design, control operation, risk treatment, compliance, incident trends, technology changes, supplier dependencies, and audit results. Control 5.4, Management responsibilities, is important because management must ensure personnel apply security according to policies and procedures, but it is not the control specifically focused on independent review. Control 5.24 concerns planning and preparation for incident management, which supports response capability but does not broadly assess the continuing suitability of the whole security approach. The phrase ''suitable, adequate and effective'' is a strong indicator of review and assurance. ISO/IEC 27002 uses independent review to challenge assumptions, detect weaknesses, and support continual improvement. Therefore, option B is the verified answer. Reference/Chapters: ISO/IEC 27002:2022, Control 5.35 Independent review of information security; Control 5.36 Compliance with policies, rules and standards for information security; Control 5.4 Management responsibilities.


Contribute your Thoughts:

0/2000 characters
Viola
7 hours ago
Control 5.35 is crucial for unbiased assessments.
upvoted 0 times
...
Kimberely
5 days ago
I feel like Control 5.24 is essential for responding to incidents, but I’m not clear on how it ties into the overall effectiveness of the security approach.
upvoted 0 times
...
Meaghan
11 days ago
Control 5.4 seems like a foundational aspect, but I wonder if it’s enough on its own without the other controls being in place.
upvoted 0 times
...
Leandro
16 days ago
I remember practicing a question similar to this, and I think incident management planning is really important, but I can't recall the specific controls.
upvoted 0 times
...
Francine
2 months ago
I think Control 5.35 about independent reviews is crucial, but I'm not entirely sure how often those should be conducted.
upvoted 0 times
...

Save Cancel