What does ISO/IEC 27002 recommend regarding audit testing?
An organization has set up a fire alarm. What type of control is this?
What should NOT be taken into account of when locating and constructing physical premises?
How many control categories (themes) does the 2022 version of ISO/IEC 27002 organize its controls into?
What is the primary purpose of control 5.13 Labelling of information?
What should an organization do if it detects a vulnerability that does not have a corresponding threat?
Which information security principle is compromised by accidental changes in information?
Which control requires the use of cryptography to protect the confidentiality, authenticity, or integrity of information?