Case 254F9B · GRC · L2 Practitioner
ISO 27001 ISMS
Practise as: Explain it · Deep dive
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- ISO/IEC 27001 specifies an Information Security Management System; clauses 4-10 are the mandatory requirements.
- Risk-driven: assess risks, choose treatments, then justify each Annex A control in a Statement of Applicability.
- 2022 revision: 93 Annex A controls in 4 themes (Organizational, People, Physical, Technological), 11 new ones.
- Certification by an accredited body: Stage 1 doc review, Stage 2 implementation audit, annual surveillance, 3-yr cycle.
- Continuous improvement (clauses 9-10): internal audits, management review, corrective actions. PDCA is implied, not named.
If the interviewer pushes back
- How does ISO 27001 certification differ in assurance value from a SOC 2 Type II report?
- What makes a Statement of Applicability defensible when you exclude an Annex A control?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.