CISM - Information Security Program - Section 3.3

Apply industry standards and frameworks to guide the design and operation of the information security programme.

Apply industry standards such as ISO/IEC 27002, NIST SP 800-53, and CIS Controls to guide the design and day-to-day operation of the information security programme. Distinguish between these standards to select the most appropriate security baselines for the organisation's sector, regulatory obligations, and maturity level.

ISO/IEC 27002NIST SP 800-53CIS ControlsSecurity baselines

Practice question for this objective

Free sampleInformation Security Programmedium

A manufacturing firm has adopted ISO/IEC 27001 for its information security management system and now wants practical guidance on how to implement the individual controls it has selected in its Statement of Applicability. Which document is the most appropriate primary reference for that implementation guidance?

  • AISO/IEC 27002, because it provides implementation guidance and good-practice detail for the information security controls referenced by the management-system standard. Correct
  • BISO/IEC 27005, because it gives the detailed configuration steps needed to deploy each selected control consistently across the estate.
  • CISO/IEC 27001 Annex A alone, because it lists the control implementation procedures in sufficient depth for an operational rollout.
  • DISO/IEC 27000, because it defines the vocabulary and overview that practitioners follow when configuring controls.
Recognise that ISO/IEC 27002 supplies the implementation guidance for controls selected under ISO/IEC 27001. ISO/IEC 27001 specifies the management system and lists controls in its annex, while ISO/IEC 27002 is the code of practice that explains how to implement and operate each of those controls, so the two are designed to be used together.

Why A is correct: Correct: ISO/IEC 27002 is the code of practice that elaborates how to implement each control, making it the natural companion when the organisation has already chosen controls under ISO/IEC 27001.

Why B is wrong: Tempting because 27005 is in the same family and is widely cited, but it addresses information security risk management, not control implementation detail, so it does not answer the need.

Why C is wrong: Tempting because Annex A is where controls are selected, but it only names and briefly states controls; it deliberately leaves implementation guidance to the companion code of practice.

Why D is wrong: Tempting because 27000 underpins the whole family, but it provides terms and an overview only and contains no control implementation guidance.

See more CISM practice questions, answers explained.

More in this domain

Back to all Information Security Program objectives, or the CISM cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.