← All CSC Flashcard Decks

ISO 27001 Controls Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 ISO 27001 Controls flashcards as text
  1. Which ISO 27001 clause requires top management to demonstrate leadership and commitment to the ISMS?

    Answer: Clause 5 – Leadership

    Clause 5 Leadership requires top management to actively demonstrate commitment by establishing policy, assigning roles, and integrating ISMS requirements into business processes.

  2. An auditor finds that an organization's access reviews have not been performed for 18 months. Which Annex A control is most directly violated?

    Answer: A.9.2.5 Review of user access rights

    A.9.2.5 Review of User Access Rights requires asset owners to review user access rights at regular intervals.

  3. What distinguishes a 'residual risk' from an 'inherent risk' in ISO 27001 risk treatment?

    Answer: Residual risk is the remaining risk after controls are applied; inherent risk is risk before controls

    Inherent risk is the raw risk level before any controls; residual risk is what remains after implementing risk treatment measures.

  4. Under Annex A control A.11, which of the following is a physical security control?

    Answer: Clear desk and clear screen policy

    A.11.2.9 Clear Desk and Clear Screen Policy is a physical and environmental security control requiring sensitive information not be left unattended.

  5. Which ISO 27001 Annex A control requires organizations to establish formal procedures for managing information security incidents?

    Answer: A.16.1.1 Responsibilities and procedures

    A.16.1.1 Responsibilities and Procedures requires management responsibilities and procedures for quick, effective incident response.

  6. An organization outsources its data processing to a cloud provider. Which Annex A control domain primarily governs this relationship?

    Answer: A.15 Supplier Relationships

    A.15 Supplier Relationships requires that risks associated with suppliers who have access to organizational information be managed through policies and monitoring.

  7. Which of the four risk treatment options in ISO 27001 involves sharing the risk with another party such as through insurance?

    Answer: Share (Transfer)

    Risk sharing (transfer) involves transferring risk to a third party, such as purchasing cyber insurance or outsourcing to a managed security provider.