You are the Chief Information Security Officer (CISO) at Apex Financial Solutions, a rapidly scaling enterprise SaaS provider. The Board of Directors has recently mandated that the organization achieve formal ISO 27001 certification within the next 12 months to satisfy stringent compliance requirements demanded by tier-one banking clients.
To ensure your GRC team does not "reinvent the wheel," you must direct them to the correct document within the ISO 27000 family. You are preparing an internal charter that explicitly defines the purpose of ISO 27002 so your implementation teams understand how it differs from ISO 27001. You must select the definition that most formally captures its intent.
Organizations frequently confuse the purpose of different standards within the ISO 27000 family. When executives mandate "ISO Compliance," teams often struggle because they try to use the *requirements* standard (27001) as a *how-to* manual. The CISO must architect a clear governance strategy by pointing teams to the correct implementation guidelines.
The business (Board, Clients) only cares about ISO 27001—the certificate on the wall that proves due diligence. Security leadership cares deeply about ISO 27002, because it is the practical "code of practice" that actually prevents breaches and operationalizes the executive mandate.
If an organization attempts to build an ISMS without utilizing ISO 27002, they will likely implement ineffective, non-standardized controls. This leads to wasted budget, failed external audits, and a higher residual risk of a security incident despite having an "ISMS" on paper.
B. is correct because it perfectly encapsulates the role of a "Code of Practice." ISO 27001 says *what* you must do (e.g., "Access to networks shall be controlled"). ISO 27002 provides the guidelines and general principles on *how* to do it (e.g., specific recommendations on network routing, firewalls, and segmentation). It specifically covers the entire lifecycle: initiating, implementing, maintaining, and improving.
Option A describes the business value of a certification audit. Option C is too narrowly focused on "giving recommendations" rather than establishing a formal, continuous governance framework. Option D is a generic statement that could apply to almost any IT standard.
Enhance your strategic decision-making skills with full-length CCISO practice scenarios.
Explore more CCISO simulations