CRISC - Information Technology and Security (20% of the exam) - Section 4.6

Apply information security concepts, frameworks and standards to protect the confidentiality, integrity and availability of assets.

Apply information security concepts - including the confidentiality, integrity, and availability triad - and frameworks such as ISO/IEC 27001 to protect organisational assets. Use a defence in depth strategy to layer complementary security controls so that failure of one layer does not result in a breach of the whole.

Confidentiality integrity availabilitySecurity frameworksISO/IEC 27001Defence in depth

Practice question for this objective

Free sampleInformation Technology and Securitymedium

An organisation is preparing for certification against ISO/IEC 27001 and management asks the risk practitioner what the standard fundamentally requires the organisation to establish. Which statement best describes the central requirement of ISO/IEC 27001?

  • AAn information security management system that is risk-based and subject to continual improvement through a recurring plan, do, check and act cycle. Correct
  • BA fixed catalogue of mandatory technical controls that every certified organisation must deploy in full regardless of its own assessed risk.
  • CA penetration testing programme run by an accredited third party at least once each quarter to confirm that perimeter defences remain effective.
  • DA documented business continuity plan that guarantees recovery of all critical services within a four hour recovery time objective.
ISO/IEC 27001 requires a risk-based information security management system maintained through continual improvement, not a fixed list of mandatory controls. ISO/IEC 27001 certifies an information security management system. Its core is a documented, risk-driven system that selects controls by assessment and improves them through the plan, do, check and act cycle, so the management system itself, not any prescribed control set, is the central requirement.

Why A is correct: ISO/IEC 27001 specifies a management system driven by risk assessment and continual improvement, which is the standard's defining requirement rather than any single control.

Why B is wrong: This is tempting because Annex A lists controls, but they are selected by risk and justified in a statement of applicability, not imposed wholesale on every organisation.

Why C is wrong: Quarterly external testing is a plausible good practice, but the standard mandates a management system rather than prescribing this specific testing cadence.

Why D is wrong: Continuity is one consideration, yet ISO/IEC 27001 does not fix a recovery time objective and is about the whole management system, not a single guaranteed target.

See more CRISC practice questions, answers explained.

Exam traps in Information Technology and Security

Answers that look right on this material and are not. Each one is a distractor from a different question in the CRISC bank for this domain.

  • It removes the need for the perimeter firewall entirely, because layered internal controls fully replace the boundary defence once enough of them are deployed.

    Why it is wrong: Tempting because layering does add internal controls, but defence in depth supplements the perimeter rather than replacing it; discarding the firewall removes one of the very layers the approach relies on.

  • It lists every information asset the organisation holds together with the monetary value assigned to each one

    Why it is wrong: Valuing assets is part of asset management and risk analysis, not the Statement of Applicability, so this confuses an input to the assessment with the control selection record.

  • Deploy the strongest available single control at the network perimeter and rely on it to block all threats

    Why it is wrong: A single strong perimeter control is exactly the single point of failure defence in depth is meant to avoid, so this contradicts the principle despite sounding robust.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.