You have been assigned the implementation of an ISMS, whose scope must cover both on premise and cloud infrastructure. Which of the following is your BEST option?
A.
Implement ISO/IEC 27002 and complement it with additional controls from the CCM.
B.
Implement ISO/IEC 27001 and complement it with additional controls from ISO/IEC 27017.
C.
Implement ISO/IEC 27001 and complement it with additional controls from ISO/IEC 27002.
D.
Implement ISO/IEC 27001 and complement it with additional controls from the NIST SP 800-145.
The best option for implementing an Information Security Management System (ISMS) that covers both on-premise and cloud infrastructure is:
**B. Implement ISO/IEC 27001 and complement it with additional controls from ISO/IEC 27017.**
ISO/IEC 27001 provides a framework for establishing, implementing, maintaining, and continually improving an ISMS, which is applicable to any organization regardless of its size or sector. It sets out the criteria for an ISMS and is the primary standard for information security management.
ISO/IEC 27017 offers additional guidance on information security controls specifically tailored for cloud services. This standard is particularly useful when the ISMS scope includes cloud infrastructure, as it provides cloud-specific controls and additional guidance that complement the general controls found in ISO/IEC 27001.
Together, ISO/IEC 27001 and ISO/IEC 27017 provide a comprehensive foundation for managing security in both on-premise and cloud environments.
The ISO/IEC 27001 standard is broadly applicable to any organization, because it provides a specification for an Information Security Management System (ISMS). ISO/IEC 27002 describes controls that can be put in place to adhere to the ISO/IEC 27001 standard. Further building on these foundational pieces, ISO published ISO/IEC 27017, which provides guidance on the information security aspects of cloud computing, recommending and assisting with the implementation of cloud-specific information security controls supplementing the guidance in ISO/IEC 27002. CCAK P# 134
upvoted 2 times
...
This section is not available anymore. Please use the main Exam Page.CCAK Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Auditor2020
4 months, 1 week ago4f2a581
11 months, 4 weeks agoOla213
1 year, 3 months agosai_murthy
1 year, 5 months ago