Open cardosec

Case 254F9B · GRC · L2 Practitioner

ISO 27001 ISMS

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. ISO/IEC 27001 specifies an Information Security Management System; clauses 4-10 are the mandatory requirements.
  2. Risk-driven: assess risks, choose treatments, then justify each Annex A control in a Statement of Applicability.
  3. 2022 revision: 93 Annex A controls in 4 themes (Organizational, People, Physical, Technological), 11 new ones.
  4. Certification by an accredited body: Stage 1 doc review, Stage 2 implementation audit, annual surveillance, 3-yr cycle.
  5. Continuous improvement (clauses 9-10): internal audits, management review, corrective actions. PDCA is implied, not named.

If the interviewer pushes back

  • How does ISO 27001 certification differ in assurance value from a SOC 2 Type II report?
  • What makes a Statement of Applicability defensible when you exclude an Annex A control?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.