exam questions

Exam Lead Implementer All Questions

View all questions & answers for the Lead Implementer exam

Exam Lead Implementer topic 1 question 21 discussion

Actual exam question from PECB's Lead Implementer
Question #: 21
Topic #: 1
[All Lead Implementer Questions]

An organization documented each security control that it implemented by describing their functions in detail. Is this compliant with ISO/IEC 27001?

  • A. No, the standard requires to document only the operation of processes and controls, so no description of each security control is needed
  • B. No, because the documented information should have a strict format, including the date, version number and author identification
  • C. Yes, but documenting each security control and not the process in general will make it difficult to review the documented information
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
Community vote distribution
C (100%)

Comments

Chosen Answer:
This is a voting comment. You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Acrisius
2 months, 2 weeks ago
Selected Answer: C
The answer here is c Yes, but documenting each security control and not the process in general will make it difficult to review the documented information ISO/IEC 27001 does not specify the form of the SoA. It requires, however that it includes a list of the information security controls, the justification for the inclusions, and actions taken to implement the selected controls.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
DP-100
Bucharest, 1 minute ago