CREST Compliance, Risk & Governance 1 — Questions and Answers
Question 1: What is the primary purpose of an Information Security Management System (ISMS) as defined by ISO/IEC 27001?
- To establish, implement, maintain, and continually improve information security controls (Correct answer)
- To automate vulnerability scanning across all systems
- To manage employee security awareness training
- To define software development lifecycle processes
Correct answer: To establish, implement, maintain, and continually improve information security controls
ISO/IEC 27001 defines an ISMS as a systematic approach to managing sensitive information to keep it secure, covering people, processes, and IT systems.
Question 2: What does a risk assessment in information security aim to identify?
- Threats, vulnerabilities, likelihood, and potential impact to organizational assets (Correct answer)
- Penetration test findings and their CVSS scores
- The number of security incidents per quarter
- Compliance gaps against a regulatory framework
Correct answer: Threats, vulnerabilities, likelihood, and potential impact to organizational assets
A risk assessment identifies what can go wrong, how likely it is, and what the impact would be, enabling informed decisions about risk treatment.
Question 3: Which of the following is a risk treatment option in information security risk management?
- Risk transfer (e.g., cyber insurance) (Correct answer)
- Risk discovery
- Risk enumeration
- Risk correlation
Correct answer: Risk transfer (e.g., cyber insurance)
Risk transfer shifts the financial consequences of a risk to a third party such as an insurer, and is one of four main risk treatment options alongside accept, avoid, and reduce.
Question 4: What does the NIST Cybersecurity Framework (CSF) organize its functions around?
- Identify, Protect, Detect, Respond, Recover (Correct answer)
- Plan, Do, Check, Act
- Prevent, Detect, Correct
- Classify, Assess, Mitigate, Monitor
Correct answer: Identify, Protect, Detect, Respond, Recover
The NIST CSF organizes cybersecurity activities into five core functions: Identify, Protect, Detect, Respond, and Recover.
Question 5: What is the difference between a vulnerability and a risk in information security?
- A vulnerability is a weakness; a risk is the potential for harm when a threat exploits that weakness (Correct answer)
- A vulnerability is the likelihood of an attack; a risk is the discovered flaw
- A vulnerability is a business impact; a risk is a technical weakness
- They are synonymous terms used interchangeably
Correct answer: A vulnerability is a weakness; a risk is the potential for harm when a threat exploits that weakness
A vulnerability is a specific weakness in a system, while risk combines the threat exploiting that vulnerability with the likelihood and potential impact.
Question 6: Which US compliance standard specifically governs the security of cardholder data for payment card processing?
- PCI DSS (Correct answer)
- HIPAA
- SOX
- FISMA
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) mandates security controls for any organization that stores, processes, or transmits payment card data.
What is the primary purpose of an Information Security Management System (ISMS) as defined by ISO/IEC 27001?