Câu 27: Lead Implementer: PECB Certified ISO/IEC 27001 Lead Implementer
An organization documented each security control that it implemented by describing their functions in detail. Is this compliant with ISO/IEC 27001?
Nội dung câu hỏi
An organization documented each security control that it implemented by describing their functions in detail. Is this compliant with ISO/IEC 27001?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. No, the standard requires to document only the operation of processes and controls, so no description of each security control is needed
- B. No, because the documented information should have a strict format, including the date, version number and author identification
- C. Yes, but documenting each security control and not the process in general will make it difficult to review the documented information — đáp án hiện tại
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.
Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.