โ† All CCP Flashcard Decks

NIST & ISO 27001 Compliance Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 NIST & ISO 27001 Compliance flashcards as text
  1. A cloud service provider wants ISO 27001 certification. Which additional ISO standard specifically extends 27001 for cloud security?

    Answer: ISO 27017

    ISO/IEC 27017 provides guidelines for information security controls applicable to the provision and use of cloud services, extending ISO 27001.

  2. Which NIST SP 800-53 control family addresses supply chain risk management?

    Answer: SR - Supply Chain Risk Management

    The SR control family was added to NIST SP 800-53 Rev. 5 specifically to address supply chain risk management practices and requirements.

  3. ISO 27001 requires organizations to set information security objectives. Which characteristic must these objectives have?

    Answer: They must be measurable and monitored

    Clause 6.2 requires information security objectives to be measurable (where practicable), monitored, communicated, and updated as appropriate.

  4. In NIST RMF, the 'Authorize' step results in which formal output?

    Answer: Authorization to Operate (ATO)

    The Authorize step (Step 5) results in an Authorizing Official issuing an Authorization to Operate (ATO), Denial of ATO, or Common Control Authorization.

  5. An organization using NIST CSF wants to communicate its current cybersecurity posture versus its desired state. What tool does the CSF provide for this?

    Answer: Current Profile and Target Profile

    CSF Profiles represent alignment of standards, guidelines, and practices to the Framework Core; comparing Current vs. Target Profiles identifies gaps.

  6. Which ISO 27001 process ensures that lessons learned from security incidents are incorporated back into the ISMS?

    Answer: Continual improvement (Clause 10)

    Clause 10 (Improvement) requires organizations to continually improve the ISMS suitability, adequacy, and effectiveness, including lessons from incidents.

  7. NIST SP 800-53A is used for which purpose?

    Answer: Assessing the effectiveness of security and privacy controls

    NIST SP 800-53A provides procedures for assessing the security and privacy controls defined in SP 800-53 to determine their effectiveness.