CSC ISO 27001 Controls 3 — Questions and Answers
Question 1: Which ISO 27001 clause requires top management to demonstrate leadership and commitment to the ISMS?
- Clause 4 – Context of the Organization
- Clause 5 – Leadership (Correct answer)
- Clause 6 – Planning
- Clause 7 – Support
Correct answer: Clause 5 – Leadership
Clause 5 Leadership requires top management to actively demonstrate commitment by establishing policy, assigning roles, and integrating ISMS requirements into business processes.
Question 2: An auditor finds that an organization's access reviews have not been performed for 18 months. Which Annex A control is most directly violated?
- A.9.1.1 Access control policy
- A.9.2.5 Review of user access rights (Correct answer)
- A.9.4.1 Information access restriction
- A.6.1.2 Segregation of duties
Correct answer: A.9.2.5 Review of user access rights
A.9.2.5 Review of User Access Rights requires asset owners to review user access rights at regular intervals.
Question 3: What distinguishes a 'residual risk' from an 'inherent risk' in ISO 27001 risk treatment?
- Residual risk exists before controls are applied; inherent risk exists after
- Residual risk is the remaining risk after controls are applied; inherent risk is risk before controls (Correct answer)
- Residual risk only applies to physical threats; inherent risk applies to cyber threats
- They are synonymous terms in the ISO 27001 standard
Correct answer: Residual risk is the remaining risk after controls are applied; inherent risk is risk before controls
Inherent risk is the raw risk level before any controls; residual risk is what remains after implementing risk treatment measures.
Question 4: Under Annex A control A.11, which of the following is a physical security control?
- Network segmentation
- Clear desk and clear screen policy (Correct answer)
- Role-based access control
- Log monitoring
Correct answer: Clear desk and clear screen policy
A.11.2.9 Clear Desk and Clear Screen Policy is a physical and environmental security control requiring sensitive information not be left unattended.
Question 5: Which ISO 27001 Annex A control requires organizations to establish formal procedures for managing information security incidents?
- A.16.1.1 Responsibilities and procedures (Correct answer)
- A.12.1.1 Documented operating procedures
- A.6.1.1 Information security roles
- A.18.1.3 Protection of records
Correct answer: A.16.1.1 Responsibilities and procedures
A.16.1.1 Responsibilities and Procedures requires management responsibilities and procedures for quick, effective incident response.
Question 6: An organization outsources its data processing to a cloud provider. Which Annex A control domain primarily governs this relationship?
- A.13 Communications Security
- A.15 Supplier Relationships (Correct answer)
- A.18 Compliance
- A.6 Organization of Information Security
Correct answer: A.15 Supplier Relationships
A.15 Supplier Relationships requires that risks associated with suppliers who have access to organizational information be managed through policies and monitoring.
Question 7: Which of the four risk treatment options in ISO 27001 involves sharing the risk with another party such as through insurance?
- Avoid
- Modify
- Share (Transfer) (Correct answer)
- Retain
Correct answer: Share (Transfer)
Risk sharing (transfer) involves transferring risk to a third party, such as purchasing cyber insurance or outsourcing to a managed security provider.
Which ISO 27001 clause requires top management to demonstrate leadership and commitment to the ISMS?