CISA - Protection of Information Assets (26% of the exam) - Section 5.1

Evaluate information asset security frameworks, standards and guidelines and physical and environmental controls.

Recognise widely used information asset security frameworks and standards - such as ISO/IEC 27001 and NIST - and explain how they structure a security programme. Evaluate physical controls and environmental controls such as access restrictions, fire suppression and power conditioning that protect IS assets.

security frameworksstandards and guidelinesphysical controlsenvironmental controls

Practice question for this objective

Free sampleProtection of Information Assetseasy

Which statement BEST describes the relationship between ISO/IEC 27001 and ISO/IEC 27002 when an IS auditor is evaluating an organisation's information security framework?

  • AISO/IEC 27001 specifies the certifiable requirements for an information security management system, while ISO/IEC 27002 provides implementation guidance for the controls referenced in Annex A. Correct
  • BISO/IEC 27001 lists detailed technical configuration baselines, while ISO/IEC 27002 lists the certifiable management system clauses that an external registrar can audit against.
  • CISO/IEC 27001 and ISO/IEC 27002 are alternative frameworks that an organisation may choose between depending on whether it wants a risk-based or a control-based approach to security.
  • DISO/IEC 27001 provides the catalogue of cryptographic algorithms, while ISO/IEC 27002 provides the risk treatment methodology that the certified organisation must adopt.
Distinguish the certifiable management system requirements in ISO/IEC 27001 from the implementation guidance role of ISO/IEC 27002. ISO/IEC 27001 establishes the requirements for an information security management system, including risk assessment, risk treatment, and Annex A controls; ISO/IEC 27002 is the companion guidance that explains how each control can be implemented, so they work together rather than as alternatives.

Why A is correct: This is correct because 27001 contains the audit-certifiable management system requirements and references Annex A controls, and 27002 is the companion guidance describing how each control may be implemented in practice.

Why B is wrong: This is tempting because both standards are well known, but the roles are reversed; configuration baselines are not in either standard and the certifiable clauses sit in 27001, not 27002.

Why C is wrong: This is tempting because candidates know multiple frameworks exist, but the two standards are complementary parts of the same family rather than alternatives chosen between.

Why D is wrong: This is tempting because cryptography and risk treatment are familiar terms, but neither standard is an algorithm catalogue and risk treatment is governed by 27001 clauses, not 27002.

See more CISA practice questions, answers explained.

Exam traps in Protection of Information Assets

Answers that look right on this material and are not. Each one is a distractor from a different question in the CISA bank for this domain.

  • Very early smoke detection apparatus installed above the suspended ceiling and beneath the raised access floor.

    Why it is wrong: This is tempting because air-sampling smoke detection is an important environmental control, but it addresses fire risk rather than power continuity.

  • It mandates a minimum number of armed guards per square metre of usable floor space across critical facilities.

    Why it is wrong: This is tempting because guards are visible physical controls, but CPTED is a design philosophy, not a staffing rule, and prescribes no guard ratios.

  • Retain only the standard mandated by the privacy regulator and discontinue the other two to remove duplication and conflict.

    Why it is wrong: Discarding the other standards loses healthcare-specific control coverage and certifiable management-system structure; reducing scope to a single regulator-mandated minimum often leaves material control gaps that the wider frameworks were already addressing.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.