ExamGecko
Question list
Search
Search

List of questions

Search

Question 99 - CCAK discussion

Report
Export

An organization has an ISMS implemented, following ISO 27001 and Annex A controls. The CIO would like to migrate some of the infrastructure to the cloud.

Which of the following standards would BEST assist in identifying controls to consider for this migration?

A.
ISO/IEC 27701
Answers
A.
ISO/IEC 27701
B.
ISO/IEC 22301
Answers
B.
ISO/IEC 22301
C.
ISO/IEC 27002
Answers
C.
ISO/IEC 27002
D.
ISO/IEC 27017
Answers
D.
ISO/IEC 27017
Suggested answer: D

Explanation:

ISO/IEC 27017 standard defines the requirements for an information security management system (ISMS). Note that the entire organization is not necessarily affected by the standard, because it all depends on the scope of the ISMS. The scope could be limited by the provider to one group within an organization, and there is no guarantee that any group outside of the scope has appropriate ISMSs in place. It is up to the auditor to verify that the scope of the engagement is "fit for purpose." As the customer, you are responsible for determining whether the scope of the certification is relevant for your purposes.

asked 18/09/2024
Ciaran Cullimore
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first