QuestionQ81

Secure Software Concepts

Many information-security standards encourage sound security practices and establish frameworks or systems for organizing the analysis and design of information-security controls. Which of the following are international information-security standards? Each correct answer represents a complete solution.

Choose all that apply.

Choose three
  • A AU audit and accountability
  • B Human resources security
  • C Organization of information security
  • D Risk assessment and treatment
Explanation

The ISO/IEC 2700x international standards establish an information security management system framework that encompasses organizational and personnel security controls and requires an information-security risk assessment and risk-treatment process. “AU” is the Audit and Accountability control family designation used by NIST, rather than an ISO/IEC international-standard category.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!