Question 1 of 30
During an audit of a financial services firm\'s information security program, an auditor discovers a critical, unpatched flaw within a proprietary trading platform\'s authentication module. This vulnerability, which allows for privilege escalation, was identified through an internal penetration test conducted after the platform\'s initial deployment. The organization\'s incident response plan has procedures for handling detected vulnerabilities, but the audit team is specifically examining the controls in place to *prevent* such flaws from being introduced during the software development lifecycle. Which ISO 27002:2022 control would be most directly applicable for assessing the organization\'s proactive measures against this type of vulnerability?
8.28 Secure coding
5.24 Information security incident management
8.16 Monitoring activities
8.23 Use of cryptography

Preparing for ISO 27002:2022 - Information Security Controls Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free