NIST & ISO 27001 Compliance Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 NIST & ISO 27001 Compliance flashcards as text
Which step in the NIST RMF involves determining if the controls implemented are effective?
Answer: Assess
The Assess step (Step 4) evaluates whether security and privacy controls are implemented correctly, operating as intended, and producing desired outcomes.
ISO 27001 requires organizations to define the scope of the ISMS. Which factor must be considered when determining scope?
Answer: Internal and external issues, interested parties, and interfaces/dependencies
ISO 27001 clause 4.3 requires scope to consider internal/external issues, requirements of interested parties, and interfaces and dependencies.
A CISO needs to select a baseline of security controls for a high-impact federal system. Which NIST resource provides the appropriate control baseline?
Answer: NIST SP 800-53B
NIST SP 800-53B provides control baselines (low, moderate, high) derived from SP 800-53 for use in federal information systems.
In ISO 27001, a Statement of Applicability (SoA) must include which elements?
Answer: Applicable controls, justification for inclusion, and justification for exclusion of Annex A controls
The SoA required by ISO 27001 clause 6.1.3 must list all Annex A controls and explain why each is included or excluded based on the risk treatment.
Which NIST CSF 2.0 core function was ADDED compared to CSF 1.1?
Answer: Govern
NIST CSF 2.0 added the Govern function to emphasize the role of governance, organizational context, and cybersecurity supply chain risk management.
Under NIST SP 800-53, what is the purpose of the 'tailoring' process?
Answer: Adjusting the baseline controls to fit specific organizational or system requirements
Tailoring allows organizations to customize baseline controls by applying scoping guidance, adding compensating controls, or specifying implementation details.
ISO 27001 certification requires a Stage 1 and Stage 2 audit. What is primarily assessed during Stage 1?
Answer: Documentation readiness and ISMS design
Stage 1 (document review) assesses whether the ISMS documentation is complete and the organization is ready for the full Stage 2 audit.