NIST & ISO 27001 Compliance Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 NIST & ISO 27001 Compliance flashcards as text
Which ISO 27001 clause addresses management review of the ISMS?
Answer: Clause 9.3
Clause 9.3 requires top management to review the ISMS at planned intervals to ensure its continuing suitability, adequacy, and effectiveness.
NIST SP 800-171 is specifically designed to protect what type of information?
Answer: Controlled Unclassified Information (CUI) in non-federal systems
NIST SP 800-171 provides requirements for protecting CUI in nonfederal information systems and organizations, commonly required by DoD contractors.
An organization finds a nonconformity during an ISO 27001 internal audit. What is the required response?
Answer: Take corrective action and evaluate its effectiveness
ISO 27001 clause 10.1 requires organizations to correct nonconformities, determine root causes, implement corrective actions, and verify their effectiveness.
In the NIST Cybersecurity Framework, 'Tiers' describe what aspect of an organization's cybersecurity program?
Answer: The rigor and sophistication of cybersecurity risk management practices
CSF Tiers (1-Partial through 4-Adaptive) characterize how an organization views cybersecurity risk and the processes in place to manage it.
Which NIST publication provides guidance on Privacy Framework and aligns with the Cybersecurity Framework?
Answer: NIST Privacy Framework 1.0
The NIST Privacy Framework (2020) is a voluntary tool that complements the CSF by providing a structure for managing privacy risk alongside cybersecurity risk.
ISO 27001 Annex A control 5.23 in the 2022 edition addresses which topic?
Answer: Information security for use of cloud services
Control 5.23 (Information security for use of cloud services) is a new control in ISO 27001:2022 addressing governance of cloud service usage.
When performing a NIST-based risk assessment, which document specifically guides the risk assessment process?
Answer: NIST SP 800-30
NIST SP 800-30 (Guide for Conducting Risk Assessments) provides the process for conducting risk assessments of federal information systems.