NIST & ISO 27001 Compliance Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 NIST & ISO 27001 Compliance flashcards as text
Which NIST SP 800-53 control family specifically addresses audit and accountability?
Answer: AU - Audit and Accountability
The AU (Audit and Accountability) control family in NIST SP 800-53 covers logging, audit record generation, and accountability requirements.
In ISO 27001:2022, what term describes the documented information that demonstrates results achieved by the ISMS?
Answer: Records
ISO 27001 distinguishes between 'documents' (information to be maintained) and 'records' (documented information providing evidence of results achieved).
A company maps its controls to both NIST CSF and ISO 27001. Which NIST CSF function aligns most closely with ISO 27001's risk treatment process?
Answer: Protect
The Protect function, which implements safeguards to ensure delivery of services, most closely maps to ISO 27001's risk treatment where controls are selected and implemented.
Under ISO 27001 Annex A (2022 edition), how many control categories exist?
Answer: 4
ISO 27001:2022 Annex A reorganized controls into 4 themes: Organizational, People, Physical, and Technological.
Which NIST document provides guidelines for applying the Risk Management Framework to federal information systems?
Answer: SP 800-37
NIST SP 800-37 (Risk Management Framework for Information Systems and Organizations) provides the six-step RMF process for federal systems.
An organization implementing ISO 27001 must conduct internal audits. Who should ideally perform these audits?
Answer: Auditors independent of the audited activity
ISO 27001 clause 9.2 requires that auditors are objective and impartial, meaning they cannot audit their own work.
NIST SP 800-61 focuses on which security domain?
Answer: Computer Security Incident Handling
NIST SP 800-61 (Computer Security Incident Handling Guide) provides guidelines for establishing and operating an incident response capability.