CCP NIST & ISO 27001 Compliance 2 — Questions and Answers
Question 1: Which NIST SP 800-53 control family specifically addresses audit and accountability?
- AU - Audit and Accountability (Correct answer)
- AC - Access Control
- IA - Identification and Authentication
- SI - System and Information Integrity
Correct answer: AU - Audit and Accountability
The AU (Audit and Accountability) control family in NIST SP 800-53 covers logging, audit record generation, and accountability requirements.
Question 2: In ISO 27001:2022, what term describes the documented information that demonstrates results achieved by the ISMS?
- Records (Correct answer)
- Policies
- Procedures
- Objectives
Correct answer: Records
ISO 27001 distinguishes between 'documents' (information to be maintained) and 'records' (documented information providing evidence of results achieved).
Question 3: A company maps its controls to both NIST CSF and ISO 27001. Which NIST CSF function aligns most closely with ISO 27001's risk treatment process?
- Respond
- Protect (Correct answer)
- Identify
- Recover
Correct answer: Protect
The Protect function, which implements safeguards to ensure delivery of services, most closely maps to ISO 27001's risk treatment where controls are selected and implemented.
Question 4: Under ISO 27001 Annex A (2022 edition), how many control categories exist?
- 4 (Correct answer)
- 14
- 18
- 35
Correct answer: 4
ISO 27001:2022 Annex A reorganized controls into 4 themes: Organizational, People, Physical, and Technological.
Question 5: Which NIST document provides guidelines for applying the Risk Management Framework to federal information systems?
- SP 800-37 (Correct answer)
- SP 800-53
- SP 800-171
- SP 800-30
Correct answer: SP 800-37
NIST SP 800-37 (Risk Management Framework for Information Systems and Organizations) provides the six-step RMF process for federal systems.
Question 6: An organization implementing ISO 27001 must conduct internal audits. Who should ideally perform these audits?
- Auditors independent of the audited activity (Correct answer)
- The CISO and security team
- External certification auditors only
- Department managers of each area
Correct answer: Auditors independent of the audited activity
ISO 27001 clause 9.2 requires that auditors are objective and impartial, meaning they cannot audit their own work.
Question 7: NIST SP 800-61 focuses on which security domain?
- Computer Security Incident Handling (Correct answer)
- Risk Assessment
- Access Control
- Cryptographic Standards
Correct answer: Computer Security Incident Handling
NIST SP 800-61 (Computer Security Incident Handling Guide) provides guidelines for establishing and operating an incident response capability.
Which NIST SP 800-53 control family specifically addresses audit and accountability?