CSC - Cybersecurity Compliance ISO 27001 Controls Questions and Answers 1 — Questions and Answers
Question 1: A financial services company is migrating its customer relationship management (CRM) system to a public cloud service. According to ISO 27001:2022 Annex A, which control specifically requires the company to establish and manage information security requirements for this transition and ongoing use?
- A.5.1 Policy for information security
- A.8.1 User endpoint devices
- A.5.23 Information security for use of cloud services (Correct answer)
- A.5.19 Information security in supplier relationships
Correct answer: A.5.23 Information security for use of cloud services
ISO 27001:2022 control A.5.23 requires organizations to establish processes for the acquisition, use, management, and exit from cloud services in accordance with their information security requirements. This control directly addresses the scenario of migrating to and using a public cloud service.
Question 2: An organization's security team has implemented a SIEM tool to collect logs from various systems. To comply with ISO 27001:2022 control A.8.16, what is the most critical next step?
- Ensure log data is encrypted at rest.
- Archive the logs for a period of seven years.
- Actively analyze the collected data for anomalous behavior. (Correct answer)
- Restrict access to the SIEM tool to senior management only.
Correct answer: Actively analyze the collected data for anomalous behavior.
ISO 27001:2022 control A.8.16, 'Monitoring activities', requires that networks, systems, and applications be monitored for anomalous behavior. Simply collecting logs (covered under A.8.15) is not sufficient; the key is the active analysis of this data to detect potential security incidents.
Question 3: A marketing manager needs to send a file containing sensitive customer data to an external printing vendor. Which of the following ISO 27001:2022 controls provides the most relevant guidance for protecting this data in transit?
- A.8.24 Use of cryptography
- A.5.10 Acceptable use of information and other associated assets
- A.5.14 Information transfer (Correct answer)
- A.7.4 Physical security monitoring
Correct answer: A.5.14 Information transfer
ISO 27001:2022 control A.5.14, 'Information transfer', mandates that rules, procedures, or agreements must be in place to protect information during all forms of transfer, whether electronic or physical, within the organization or to third parties. This directly applies to sending sensitive data to an external vendor.
Question 4: A company is developing a new remote work policy. To align with ISO 27001:2022 control A.6.7, which of the following aspects is MOST crucial to include?
- A list of approved company holidays.
- Requirements for employees' internet connection speed.
- A clause mandating the use of company-provided coffee mugs.
- Security measures for information accessed, processed, or stored outside the organization's premises. (Correct answer)
Correct answer: Security measures for information accessed, processed, or stored outside the organization's premises.
ISO 27001:2022 control A.6.7, 'Remote working', requires that security measures be implemented when personnel are working remotely to protect information accessed, processed, or stored outside the organization's premises. This includes technical, physical, and procedural controls.
Question 5: Which of the following ISO 27001:2022 controls is considered a 'Technological' control?
- A.6.3 Information security awareness, education and training
- A.5.1 Policies for information security
- A.8.28 Secure coding (Correct answer)
- A.7.2 Physical entry
Correct answer: A.8.28 Secure coding
In the ISO 27001:2022 revision, controls are grouped into four themes: Organisational, People, Physical, and Technological. A.8.28 'Secure coding' is explicitly listed under the Technological controls theme, as it pertains to the technical implementation of security within software.
Question 6: A hospital's IT team is concerned about ransomware attacks. They have implemented antivirus software on all endpoints and servers. To enhance their defenses in line with ISO 27001 principles for malware protection, what additional measure should they prioritize?
- Conducting user awareness training on phishing and social engineering. (Correct answer)
- Increasing the physical security of the data center.
- Negotiating lower software licensing fees with the antivirus vendor.
- Decommissioning all legacy operating systems immediately.
Correct answer: Conducting user awareness training on phishing and social engineering.
While antivirus software is a crucial technical control for malware protection (related to the former A.12.2.1 and now part of broader technological controls like A.8.7), a comprehensive defense must also address the human element. Many malware incidents, including ransomware, begin with phishing or social engineering attacks. Therefore, user awareness training (A.6.3) is a critical preventative measure to complement technical controls.
A financial services company is migrating its customer relationship management (CRM) system to a public cloud service.
According to ISO 27001:2022 Annex A, which control specifically requires the company to establish and manage information security requirements for this transition and ongoing use?