CCP NIST & ISO 27001 Compliance 3 — Questions and Answers
Question 1: Which step in the NIST RMF involves determining if the controls implemented are effective?
- Assess (Correct answer)
- Implement
- Authorize
- Monitor
Correct answer: Assess
The Assess step (Step 4) evaluates whether security and privacy controls are implemented correctly, operating as intended, and producing desired outcomes.
Question 2: ISO 27001 requires organizations to define the scope of the ISMS. Which factor must be considered when determining scope?
- Internal and external issues, interested parties, and interfaces/dependencies (Correct answer)
- Only the IT infrastructure and data centers
- The number of employees and budget
- The organization's revenue and market size
Correct answer: Internal and external issues, interested parties, and interfaces/dependencies
ISO 27001 clause 4.3 requires scope to consider internal/external issues, requirements of interested parties, and interfaces and dependencies.
Question 3: A CISO needs to select a baseline of security controls for a high-impact federal system. Which NIST resource provides the appropriate control baseline?
- NIST SP 800-53B (Correct answer)
- NIST SP 800-30
- NIST SP 800-137
- NIST SP 800-61
Correct answer: NIST SP 800-53B
NIST SP 800-53B provides control baselines (low, moderate, high) derived from SP 800-53 for use in federal information systems.
Question 4: In ISO 27001, a Statement of Applicability (SoA) must include which elements?
- Applicable controls, justification for inclusion, and justification for exclusion of Annex A controls (Correct answer)
- Only the list of implemented controls
- Risk treatment options and residual risk levels
- Names of control owners and implementation dates
Correct answer: Applicable controls, justification for inclusion, and justification for exclusion of Annex A controls
The SoA required by ISO 27001 clause 6.1.3 must list all Annex A controls and explain why each is included or excluded based on the risk treatment.
Question 5: Which NIST CSF 2.0 core function was ADDED compared to CSF 1.1?
- Govern (Correct answer)
- Protect
- Detect
- Recover
Correct answer: Govern
NIST CSF 2.0 added the Govern function to emphasize the role of governance, organizational context, and cybersecurity supply chain risk management.
Question 6: Under NIST SP 800-53, what is the purpose of the 'tailoring' process?
- Adjusting the baseline controls to fit specific organizational or system requirements (Correct answer)
- Removing all controls that are too expensive to implement
- Selecting only preventive controls for a system
- Mapping controls to compliance frameworks
Correct answer: Adjusting the baseline controls to fit specific organizational or system requirements
Tailoring allows organizations to customize baseline controls by applying scoping guidance, adding compensating controls, or specifying implementation details.
Question 7: ISO 27001 certification requires a Stage 1 and Stage 2 audit. What is primarily assessed during Stage 1?
- Documentation readiness and ISMS design (Correct answer)
- Operational effectiveness of all controls
- Physical security of data centers
- Employee security awareness scores
Correct answer: Documentation readiness and ISMS design
Stage 1 (document review) assesses whether the ISMS documentation is complete and the organization is ready for the full Stage 2 audit.
Which step in the NIST RMF involves determining if the controls implemented are effective?