ISO 27001 Controls Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 ISO 27001 Controls flashcards as text
Under ISO 27001 Annex A, which control category addresses the management of removable media?
Answer: A.12 Operations Security
A.12 Operations Security includes A.12.3, which covers information backup and media handling including removable media.
What is the primary purpose of a Statement of Applicability (SoA) in ISO 27001?
Answer: To document which Annex A controls are applicable and justify exclusions
The SoA documents every Annex A control, states whether it is applied, and provides justification for any exclusions.
ISO 27001 control A.14 covers which domain?
Answer: System Acquisition, Development and Maintenance
A.14 System Acquisition, Development and Maintenance ensures security requirements are addressed throughout the software development lifecycle.
Which ISO 27001 Annex A control specifically requires organizations to screen personnel before employment?
Answer: A.7.1.1 Screening
A.7.1.1 Screening requires background verification checks on candidates for employment in accordance with laws and regulations.
An organization wants to ensure that security patches are applied within 30 days of release. Which Annex A control supports this requirement?
Answer: A.12.6.1 Management of technical vulnerabilities
A.12.6.1 Management of Technical Vulnerabilities requires timely identification and remediation of technical vulnerabilities including patching.
Which control under ISO 27001 Annex A addresses the use of cryptographic controls and key management?
Answer: A.10.1 Cryptographic controls
A.10.1 Cryptographic Controls requires a policy on the use of cryptographic controls and proper management of cryptographic keys.
In ISO 27001, what does the control A.17.1 address?
Answer: Information security continuity
A.17.1 Information Security Continuity requires that information security continuity is embedded in the organization's business continuity management.