What is the Statement of Applicability (SOA) and what should it be consistent with?
A) The SOA is the end-product of the risk-assessment process and should be consistent with the ISMS policy developed in the early stages of the PDAC process.
B) The SOA is the first draft of the risk-assessment process should be consistent with the ISMS policy developed in the early stages of the PDAC process.
C) The SOA is the end-product of the risk-assessment process and should be contradictive to the ISMS policy developed in the later stages of the PDAC process.
D) The SOA should be consistent with the risk assessment standards found in ISO 9002.
Correct Answer:
Verified
Q8: What does a Gap Analysis focus on?
A)
Q9: The levels of Evaluation Assurance Levels do
Q10: The ISO "Family" that promulgates information security
Q11: _ are systems-related individuals or events that
Q12: What are the three options when dealing
Q14: Which of the following best describes and
Q15: An organizational internal control process that ensures
Q16: When developing an ISMS, how many phases
Q17: Which of the following are levels of
Q18: What are the 3 ISMS security objectives?
A)
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents