The answer here is B
The statement of applicability or SoA
Contains
All necessary controls and for each
Justification for inclusion
Whether the controls implemented or not
Justification for exclusion
Development of the SoA is part of the risk treatment process
As per ISO27005 after it has prioritised the risk for risk treatment the organisation
Determines the controls and develops the SoA then risk plan.
See PECB day 2 page 139
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Acrisius
2 months ago