CISSP PRACTICE QUESTIONS – 20220216

Effective CISSP Questions

The international standard, ISO/IEC 27002:2022, has been officially published on Feb 15th, 2022. Each control in the standard has been associated with five attributes with corresponding attribute values. Which of the following is not a value of the control type attribute? (Wentz QOTD)
A. Preventive
B. Detective
C. Corrective
D. Recovery


Kindly be reminded that the suggested answer is for your reference only. It doesn’t matter whether you have the right or wrong answer. What really matters is your reasoning process and justifications.

My suggested answer is D. Recovery.

Wentz’s book, The Effective CISSP: Security and Risk Management, helps CISSP and CISM aspirants build a solid conceptual security model. It is a tutorial for information security and a supplement to the official study guides for the CISSP and CISM exams and an informative reference for security professionals.

ISO/IEC 27002:2022 Controls by Security Properties and Control Types
ISO/IEC 27002:2022 Controls by Security Properties and Control Types
ISO/IEC 27002:2022 Controls by Cybersecurity Concepts and Security Domains
ISO/IEC 27002:2022 Controls by Cybersecurity Concepts and Security Domains

There are 93 distinct controls introduced in ISO/IEC 27002:2022. They are categorized as:
a) people, if they concern individual people;
b) physical, if they concern physical objects;
c) technological, if they concern technology;
d) otherwise they are categorized as organizational.

ISO 27002 ControlsDownload

Control Taxonomy

Each control is associated with five attributes with corresponding attribute values (preceded by “#” to make them searchable), as follows:

  • Control type: Preventive, Detective, and Corrective.
  • Information security properties: Confidentiality, Integrity and Availability.
  • Cybersecurity concepts: Identify, Protect, Detect, Respond and Recover.
  • Operational capabilities: as the following list shows.
  • Security domains: Governance_and_Ecosystem, Protection, Defence and Resilience

Operational Capabilities

  1. Governance
  2. Asset_management
  3. Information_protection
  4. Human_resource_security
  5. Physical_security
  6. System_and_network_security
  7. Application_security
  8. Secure_configuration
  9. Identity_and_access_management
  10. Threat_and_vulnerability_management
  11. Continuity
  12. Supplier_relationships_security
  13. Legal_and_compliance
  14. Information_security_event_management
  15. Information_security_assurance
#Information_security_assurance as an attribute of operational capabilities
#Information_security_assurance as an attribute of operational capabilities

Reference


國際標準 ISO/IEC 27002:2022 已於 2022 年 2 月 15 日正式發布。標準中的每個控件都與具有相應屬性值的五個屬性相關聯。 以下哪一項不是控件類型(control type)屬性的值? (Wentz QOTD)
A. 預防 (preventive)
B. 偵測 (detective)
C. 糾正 (corrective)
D. 恢復 (recovery)

Leave a Reply