Free ISO 27000 Foundation Annex A Control Themes Questions and Answers — Questions and Answers
Question 1: The 2022 revision of ISO/IEC 27001 restructured the Annex A controls into four high-level themes. Which of the following correctly lists these four themes?
- Access Control, Cryptography, Operations Security, and Communications Security
- Policies, Procedures, Technical Implementations, and Physical Safeguards
- Organizational, People, Physical, and Technological (Correct answer)
- Risk Assessment, Asset Management, Incident Management, and Business Continuity
Correct answer: Organizational, People, Physical, and Technological
The ISO/IEC 27001:2022 standard updated Annex A by consolidating the previous 14 domains into four distinct themes: A.5 Organizational controls, A.6 People controls, A.7 Physical controls, and A.8 Technological controls. This structure simplifies the categorization of the 93 controls.
Question 2: An organization is implementing a new mandatory security awareness training program and updating its disciplinary process for information security policy violations. Under which ISO/IEC 27001:2022 Annex A theme would these controls primarily be classified?
- Organizational controls
- People controls (Correct answer)
- Technological controls
- Physical controls
Correct answer: People controls
Controls related to the human element of security, such as screening, awareness training, and disciplinary processes, fall under the 'People controls' theme (A.6). This theme focuses on mitigating risks associated with human error or malicious action throughout the employment lifecycle.
Question 3: An IT department is focused on implementing data leakage prevention measures, managing the secure configuration of servers, and deploying malware protection. These activities are most representative of which Annex A control theme?
- People controls
- Physical controls
- Organizational controls
- Technological controls (Correct answer)
Correct answer: Technological controls
Controls such as data leakage prevention (A.8.12), configuration management (A.8.9), and protection against malware (A.8.7) are all examples of 'Technological controls' (A.8). This theme covers the technical safeguards applied to systems, networks, and applications to protect information.
Question 4: Which of the following controls is primarily categorized under the 'Physical controls' theme (A.7) in ISO/IEC 27001:2022 Annex A?
- Securing offices, rooms, and facilities (Correct answer)
- Information security for use of cloud services
- Information security awareness, education, and training
- Management of technical vulnerabilities
Correct answer: Securing offices, rooms, and facilities
Securing offices, rooms, and facilities (A.7.3) is a core component of the 'Physical controls' theme. This theme is concerned with preventing unauthorized physical access, damage, and interference to the organization's premises and the information within them.
Question 5: A company is defining its overall information security policies, assigning security roles and responsibilities, and establishing its process for information classification. These foundational activities fall under which Annex A control theme?
- People controls
- Technological controls
- Organizational controls (Correct answer)
- Physical controls
Correct answer: Organizational controls
The 'Organizational controls' theme (A.5) establishes the governance framework for the ISMS. This includes creating policies (A.5.1), defining roles and responsibilities (A.5.2), and classifying information (A.5.12), which are all high-level, process-oriented controls.
Question 6: An auditor is reviewing a company's 'clear desk and clear screen' policy and the measures taken to secure equipment located off-premises. These specific controls are key components of which Annex A theme?
- Technological controls
- Physical controls (Correct answer)
- Organizational controls
- People controls
Correct answer: Physical controls
Both the 'clear desk and clear screen' policy (A.7.7) and the security of assets off-premises (A.7.9) are classified under 'Physical controls' (A.7). These controls aim to reduce the risk of unauthorized access, loss, and damage to information and equipment in the physical environment, whether on-site or remote.
The 2022 revision of ISO/IEC 27001 restructured the Annex A controls into four high-level themes.
Which of the following correctly lists these four themes?