CSC ISO 27001 Controls 2 — Questions and Answers
Question 1: Under ISO 27001 Annex A, which control category addresses the management of removable media?
- A.8 Asset Management
- A.9 Access Control
- A.12 Operations Security (Correct answer)
- A.13 Communications Security
Correct answer: A.12 Operations Security
A.12 Operations Security includes A.12.3, which covers information backup and media handling including removable media.
Question 2: What is the primary purpose of a Statement of Applicability (SoA) in ISO 27001?
- To list all identified risks and their scores
- To document which Annex A controls are applicable and justify exclusions (Correct answer)
- To record all security incidents during the audit period
- To define the ISMS scope boundaries
Correct answer: To document which Annex A controls are applicable and justify exclusions
The SoA documents every Annex A control, states whether it is applied, and provides justification for any exclusions.
Question 3: ISO 27001 control A.14 covers which domain?
- Supplier Relationships
- System Acquisition, Development and Maintenance (Correct answer)
- Incident Management
- Business Continuity Management
Correct answer: System Acquisition, Development and Maintenance
A.14 System Acquisition, Development and Maintenance ensures security requirements are addressed throughout the software development lifecycle.
Question 4: Which ISO 27001 Annex A control specifically requires organizations to screen personnel before employment?
- A.6.1.1 Information security roles and responsibilities
- A.7.1.1 Screening (Correct answer)
- A.7.2.1 Management responsibilities
- A.8.1.1 Inventory of assets
Correct answer: A.7.1.1 Screening
A.7.1.1 Screening requires background verification checks on candidates for employment in accordance with laws and regulations.
Question 5: An organization wants to ensure that security patches are applied within 30 days of release. Which Annex A control supports this requirement?
- A.12.6.1 Management of technical vulnerabilities (Correct answer)
- A.12.1.2 Change management
- A.14.2.2 System change control procedures
- A.16.1.3 Reporting information security weaknesses
Correct answer: A.12.6.1 Management of technical vulnerabilities
A.12.6.1 Management of Technical Vulnerabilities requires timely identification and remediation of technical vulnerabilities including patching.
Question 6: Which control under ISO 27001 Annex A addresses the use of cryptographic controls and key management?
- A.10.1 Cryptographic controls (Correct answer)
- A.12.3 Backup
- A.13.1 Network security management
- A.8.3 Media handling
Correct answer: A.10.1 Cryptographic controls
A.10.1 Cryptographic Controls requires a policy on the use of cryptographic controls and proper management of cryptographic keys.
Question 7: In ISO 27001, what does the control A.17.1 address?
- Compliance with legal and contractual requirements
- Information security continuity (Correct answer)
- Supplier service delivery management
- Security in project management
Correct answer: Information security continuity
A.17.1 Information Security Continuity requires that information security continuity is embedded in the organization's business continuity management.
Under ISO 27001 Annex A, which control category addresses the management of removable media?