โ† All CSC Flashcard Decks

ISO 27001 Controls Flashcards

7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 ISO 27001 Controls flashcards as text
  1. ISO 27001's Annex A control A.6.1.2 requires segregation of duties. Which scenario BEST demonstrates a violation of this control?

    Answer: A system administrator both requests and approves privileged access for themselves

    Segregation of duties means no single individual should control all phases of a critical process; a sysadmin self-approving privileged access is a direct violation.

  2. Which ISO 27001 Annex A control addresses the requirement to protect organizational information accessed or processed by teleworkers?

    Answer: A.6.2.2 Teleworking

    A.6.2.2 Teleworking requires a policy and supporting security measures to protect information accessed, processed, or stored at teleworking sites.

  3. During a management review, leadership discovers the ISMS objectives have not been met. According to ISO 27001 Clause 10, what must the organization do?

    Answer: Take corrective actions to address nonconformities and improve the ISMS

    Clause 10.1 Nonconformity and Corrective Action requires the organization to react to nonconformity and take action to eliminate causes and prevent recurrence.

  4. What is the main objective of Annex A control A.18.2 (Information Security Reviews)?

    Answer: To verify compliance of information processing with security policies and standards

    A.18.2 Information Security Reviews requires that the ISMS and its implementation be reviewed independently to ensure compliance with policies and standards.

  5. A company processes credit card data and must comply with PCI DSS in addition to ISO 27001. How should the organization handle both frameworks?

    Answer: Use ISO 27001 as the base ISMS framework and map PCI DSS requirements to applicable controls

    Best practice is to use ISO 27001 as the overarching framework and map additional regulatory requirements like PCI DSS to the corresponding controls to reduce duplication.

  6. Which term describes the documented link between identified risks and the Annex A controls chosen to treat them?

    Answer: Risk Treatment Plan

    The Risk Treatment Plan documents the selected controls, reasons for selection, and the responsible parties, directly linking risks to their treatment controls.

  7. An organization's ISMS scope covers only its London office but the company has offices in five countries. Under ISO 27001, which statement is TRUE?

    Answer: A partial scope is permitted provided interfaces and dependencies with out-of-scope areas are addressed

    ISO 27001 allows organizations to define a partial scope, but Clause 4.3 requires that interfaces and dependencies with out-of-scope areas be identified and considered.