Question 1
(Topic 1)
ISO/IEC 27001:2013 uses the term “comprehensive list of controls”, whereas ISO/IEC 27001:2022 uses the term “list of possible information security controls.” Does this change affect the requirements of the standard? Reveal Solution Hide Solution Discussion Correct Answer: C 🗳️
Select an option, then click Submit answer.
- ○ Yes, the new version of the standard allows organizations to decide which controls will be implemented as they are not mandatory anymore
- ○ No, this change affects the requirements specified in Annex A of ISO/IEC 27001:2013 but not in main clauses of the standard
- ○ No, this is a technical revision which does not affect the content of clauses or requirements of ISO/IEC 27001:2013