ISO 27001 Controls Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 ISO 27001 Controls flashcards as text
Which ISO 27001 clause specifically requires the organization to conduct internal ISMS audits at planned intervals?
Answer: Clause 9 – Performance Evaluation
Clause 9.2 Internal Audit requires the organization to conduct internal audits at planned intervals to provide information on whether the ISMS conforms to requirements.
Under Annex A control A.12.4, what must organizations do to comply with logging and monitoring requirements?
Answer: Produce, protect, and regularly review event logs recording user activities and security events
A.12.4.1 Event Logging requires logs of user activities, exceptions, and security events to be produced, kept, and regularly reviewed.
A software developer wants to test an application using a copy of live production data. Which ISO 27001 control most directly applies?
Answer: A.14.3.1 Protection of test data
A.14.3.1 Protection of Test Data requires that operational data used for testing be carefully selected, protected, and controlled.
What is the correct sequence for conducting an ISO 27001 risk assessment?
Answer: Identify risks → Analyze risks → Evaluate risks → Select treatment options
ISO 27001 Clause 6.1.2 defines the risk assessment process as: identify risks, analyze (likelihood/impact), evaluate against criteria, then determine treatment.
Which Annex A control requires that information classification labels be applied to information assets?
Answer: A.8.2.2 Labelling of information
A.8.2.2 Labelling of Information requires that an appropriate set of procedures for information labelling be developed and implemented.
An employee is leaving the organization. Under ISO 27001, which control ensures their access is revoked in a timely manner?
Answer: A.9.2.6 Removal or adjustment of access rights
A.9.2.6 Removal or Adjustment of Access Rights requires that access rights of employees be removed upon termination of employment or contract.
What document must an ISO 27001-certified organization maintain to prove it has addressed all mandatory requirements of Annex A?
Answer: Statement of Applicability (SoA)
The Statement of Applicability is a mandatory document listing all Annex A controls with justifications for inclusion or exclusion.