Domain 1: Security and Risk Management - Security Frameworks - ISO/IEC 27000 Series

28 important questions on Domain 1: Security and Risk Management - Security Frameworks - ISO/IEC 27000 Series

When and by who was the British Standard 7799 (BS7799) developed?

It was developed in 1995 by the United Kingdom government's Department of Trade and Industry and published by the British Standards Institution.

What was the BS 7799 about?

The standard outlined how information security management systems (ISMS, aka Security Program) should be build and maintained.

Why is a security management system (framework) important?

Because it gives a holistic view of all the different controls (administrative, physical, technical) that are being applied.
  • Higher grades + faster learning
  • Never study anything twice
  • 100% sure, 100% understanding
Discover Study Smart

How many parts did the BS7799 had?

2 parts

The BS7799 was a de facto standard. What does de facto mean?

That it was not a demand to follow the standard, but it was being used by choice.

What versions of the BS7799 can you name?

1. BS7799V1
2. BS7799V2
3. ISO 17799
4. BS7799-3:2005

Where does IEC stand for?

International Electrotechnical Commission

How many countries is ISO in?

162 countries around the world

Where is ISO/IEC 27000 about?

Overview and vocabulary

Where is ISO/IEC 27001 about?

ISMS requirements

Where is ISO/IEC 27002 about?

Code of practice for information security controls

Where is ISO/IEC 27003 about?

ISMS implementation

Where is ISO/IEC 27004 about?

ISMS measurement

Where is ISO/IEC 27005 about?

Risk management

Where is ISO/IEC 27006 about?

Certification body requirements

Where is ISO/IEC 27007 about?

ISMS auditing

Where is ISO/IEC 27008 about?

Guidance for auditors

Where is ISO/IEC 27011 about?

Telecommunications organizations

Where is ISO/IEC 27015 about?

Financial sector

Where is ISO/IEC 27031 about?

Business continuity

Where is ISO/IEC 27032 about?

Cybersecurity

Where is ISO/IEC 27033 about?

Network security

Where is ISO/IEC 27034 about?

Application security

Where is ISO/IEC 27035 about?

Incident management

Where is ISO/IEC 27037 about?

Digital evidence collection and preservation

Where is ISO/IEC 27799 about?

Health organizations

Where is the ISO/IEC 27000 series for?

To serve as industry best practices for the management of security controls in a holistic manner within organizations

Which part of the ISO/IEC 27000 series is being used for certification by an accredited third party?

ISO/IEC 270001

The question on the page originate from the summary of the following study material:

  • A unique study and practice tool
  • Never study anything twice again
  • Get the grades you hope for
  • 100% sure, 100% understanding
Remember faster, study better. Scientifically proven.
Trustpilot Logo