ISO/IEC 27009:2016 Sector-specific Application of ISO/IEC 27001 Exam Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

When a sector-specific regulatory framework, such as the proposed \"Digital Health Data Protection Act\" (DHDPA) for a nation\'s healthcare sector, mandates specific information security controls that are not explicitly detailed in ISO/IEC 27001:2013 Annex A, how should an organization seeking ISO/IEC 27001 certification, and leveraging ISO/IEC 27009:2016 for sector-specific application, best integrate these DHDPA requirements into its Information Security Management System (ISMS)?

Identify and implement the DHDPA-mandated controls as additional controls within the ISMS, ensuring they are documented in the Statement of Applicability and mapped to relevant ISO/IEC 27001 clauses or Annex A controls where applicable, or treated as standalone requirements if no direct mapping exists.
Assume that existing ISO/IEC 27001:2013 Annex A controls implicitly cover the DHDPA requirements, and therefore no additional documentation or implementation is necessary beyond the standard ISMS.
Prioritize only those DHDPA requirements that have a direct, explicit match with controls listed in ISO/IEC 27001:2013 Annex A, disregarding any DHDPA controls that are unique or more stringent.
Seek an exemption from the DHDPA by demonstrating compliance with the general principles of ISO/IEC 27001:2013, arguing that the sector-specific act is redundant if a robust ISMS is in place.

About the ISO/IEC 27009:2016 Sector-specific Application of ISO/IEC 27001 Exam Certification

These free practice questions are designed to help you assess your readiness for the ISO/IEC 27009:2016 Sector-specific Application of ISO/IEC 27001 Exam exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.