CRISC - Information Technology and Security - Section 4.6

Apply information security concepts, frameworks and standards to protect the confidentiality, integrity and availability of assets.

Apply information security concepts - including the confidentiality, integrity, and availability triad - and frameworks such as ISO/IEC 27001 to protect organisational assets. Use a defence in depth strategy to layer complementary security controls so that failure of one layer does not result in a breach of the whole.

Confidentiality integrity availabilitySecurity frameworksISO/IEC 27001Defence in depth

Practice question for this objective

Free sampleInformation Technology and Securitymedium

An organisation is preparing for certification against ISO/IEC 27001 and management asks the risk practitioner what the standard fundamentally requires the organisation to establish. Which statement best describes the central requirement of ISO/IEC 27001?

  • AAn information security management system that is risk-based and subject to continual improvement through a recurring plan, do, check and act cycle. Correct
  • BA fixed catalogue of mandatory technical controls that every certified organisation must deploy in full regardless of its own assessed risk.
  • CA penetration testing programme run by an accredited third party at least once each quarter to confirm that perimeter defences remain effective.
  • DA documented business continuity plan that guarantees recovery of all critical services within a four hour recovery time objective.
ISO/IEC 27001 requires a risk-based information security management system maintained through continual improvement, not a fixed list of mandatory controls. ISO/IEC 27001 certifies an information security management system. Its core is a documented, risk-driven system that selects controls by assessment and improves them through the plan, do, check and act cycle, so the management system itself, not any prescribed control set, is the central requirement.

Why A is correct: ISO/IEC 27001 specifies a management system driven by risk assessment and continual improvement, which is the standard's defining requirement rather than any single control.

Why B is wrong: This is tempting because Annex A lists controls, but they are selected by risk and justified in a statement of applicability, not imposed wholesale on every organisation.

Why C is wrong: Quarterly external testing is a plausible good practice, but the standard mandates a management system rather than prescribing this specific testing cadence.

Why D is wrong: Continuity is one consideration, yet ISO/IEC 27001 does not fix a recovery time objective and is about the whole management system, not a single guaranteed target.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Information Technology and Security objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.