首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
The following scenario will be used for questions 26, 27, and 28. Trent is the new manager of his company’s internal software de
The following scenario will be used for questions 26, 27, and 28. Trent is the new manager of his company’s internal software de
admin
2013-12-19
84
问题
The following scenario will be used for questions 26, 27, and 28.
Trent is the new manager of his company’s internal software development department. He has been told by his management that the group needs to be compliant with the international standard that provides guidance to organizations in integrating security into the processes used for managing their applications. His new boss told him that he should join and get familiar with the Web Application Security Consortium, and Trent just received an e-mail stating that one of the company’s currently deployed applications has a zero day vulnerability.
Which of the following is most likely the standard Trent’s company wants to comply with?
选项
A、ISO/IEC 27005
B、ISO/IEC 27001
C、ISO/IEC 27034
D、BS 7799
答案
C
解析
C正确。ISO/IEC 27034是一个国际标准,它为组织将安全性整合到用于管理应用程序的流程提供了指南。它适用于内部开发的应用程序、从第三方获得的应用程序以及应用程序的开发和运算是外包的情况。
A不正确。因为ISO/IEC 27005:2001为信息安全风险管理提供了指导方针。ISO/IEC 27005:2001支持ISO/IEC 27001,并且它的设计是为了帮助基于风险管理方法的信息安全的正确实现。
B不正确。因为ISO/IEC 27001:2005详细说明了在组织的整体业务风险的情况中,建立、实现、运行、监控、审查、维护和提高文档化的信息安全管理系统的需求。它还详细说明了依单个组织或单个组织的部分部门而定制的安全控制实现的需求。
D不正确。因为BS 7799是由英国政府的贸易与工业部所撰写的,它概述了信息安全管理体系(Information Security Management,ISMS,又叫安全项目)应该如何构建和维护。它的目的是为组织提供如何设计、实现和维护政策、过程和技术,以管理其敏感信息资产的风险提供指导方针。
转载请注明原文地址:https://kaotiyun.com/show/lNhZ777K
0
CISSP认证
相关试题推荐
Themassmediaisabigpartofourculture,yetitcanalsobeahelper,adviserandteachertoouryounggeneration.Themass
TheTreasurycouldpocket20millionayearinextrafinesoncethecountry’sspeedcameranetworkisexpanded.Motoringorgani
Individualsandbusinesseshavelegalprotectionforintellectualpropertytheycreateandown.Intellectualproper【C1】______fro
Backinthe1990s,awell-knowncomputerscientisthadanunusualwayofintroducinghimselftowomen.Accordingtoindustrylor
In2009theEuropeanCommissioncarriedoutaninvestigationintoMicrosoft.TheAmericansoftwaregianttiedInternetExplorer,
BarackObama,inhisstate-of-the-unionspeechonFebruary12th,calledforaneweraofscientificdiscovery."Nowitisthet
Themoreparentstalktotheirchildren,thefasterthosechildren’svocabulariesgrowandthebettertheirintelligencedevelop
Fewthingssay"forgetI’mhere"quitesoeloquentlyastheposeoftheshy—theavertedgaze,thehunchedshoulders,thebodypi
Fewthingssay"forgetI’mhere"quitesoeloquentlyastheposeoftheshy—theavertedgaze,thehunchedshoulders,thebodypi
DespiteincreasedairportsecuritysinceSeptember11th,2001,thetechnologytoscanbothpassengersandbaggageforweaponsan
随机试题
下列哪一项是人类小脑半球中间部受损时所特有的症状
胁痛的主要病机有
保健门诊护士不能从事的工作是
下列说法中,不正确的是()。
商业银行负债业务创新的最终目的是创造()。
请从所给的四个选项中,选择最合适的一个填在问号处,使之呈现一定的规律性:
下列关于RPR技术的描述中,错误的是()。
使用白盒测试方法时,设计测试用例应根据()。
数据字典是各类数据描述的集合,它通常包括5个部分,即数据项、数据结构、数据流;______和处理过程。
Itdoesn’tmakemuchdifferencewhetherhecanfinishthiswork.
最新回复
(
0
)