skip to content

Infosec Frameworks & Certification

ISO 27001, SOC 2, NIST, PCI DSS, CIS and HIPAA: the control frameworks security programs are audited against. Interviewers probe whether you can run security through controls, evidence and audits.

part ofCompliance & governance standardsoverview, primer and where to startread it →
on this pageshow

explore

questions

page 1 of 2

In security compliance, how do certification (ISO/IEC 27001), attestation (SOC 2) and self-assessment differ in who evaluates and what results?

level: juniorimportance: must knowfreq 55%

answer

  1. certificate versus opinion
  2. who signs the conclusion
  3. CPA practitioner, examination engagement
  4. affirmation by your own official

basics

~20 s

Certification means an independent body audits you against a standard and issues a certificate, as with ISO/IEC 27001. Attestation means a CPA practitioner gives an opinion against criteria, as in SOC 2. Self-assessment means you evaluate yourself and an official affirms it.

solid answer

~50 s

The difference is **who reaches the conclusion and what they issue**. In **certification**, an independent certification body audits the organization against a standard's requirements and issues a **certificate** of conformity - ISO/IEC 27001 is the usual example; CMMC Level 2 (C3PAO) is a *certification assessment* by an authorized or accredited third party. In **attestation**, a CPA - called a **practitioner** under the AICPA attestation standards - performs an **examination engagement** and expresses an **opinion** on subject matter or management's assertion against a set of criteria; a SOC 2 report is an attestation report on controls against the Trust Services Criteria, not a certificate. In **self-assessment**, the organization evaluates itself and a responsible official **affirms** the result, as in CMMC Level 2 (Self) or a PCI DSS Self-Assessment Questionnaire. Customers weigh them differently because independence and the report's content differ.

go deeper

for a junior

Recall the three models and one example of each: ISO/IEC 27001 certification, SOC 2 attestation, and a self-assessment with affirmation.

for a middle

Explain what each output actually asserts: a certificate of conformity, a practitioner's opinion against criteria, or an organization's affirmed self-evaluation.

for a senior

Show how you would answer a customer asking for assurance: which output fits their question, and how scope and period limit what any of them proves.

for a principal

Weigh which assurance model to pursue first given customer demand, cost and how much detail buyers need to see.

## Three ways to reach a compliance conclusion Candidates often say "we are SOC 2 certified". Interviewers use that phrase to test whether the candidate knows what their organization actually holds. The three models differ in **who evaluates**, **what standard of evidence applies** and **what document results**. | Model | Who evaluates | What results | Examples | |---|---|---|---| | **Certification** | An independent certification body, itself accredited | A certificate stating conformity with a standard, maintained by periodic audits | ISO/IEC 27001; CMMC Level 2 (C3PAO) and Level 3 (DIBCAC) certification assessments | | **Attestation** | A CPA practitioner under the AICPA attestation standards | A report containing the practitioner's opinion against stated criteria | SOC 2 examination against the Trust Services Criteria | | **Self-assessment** | The organization itself | Its own results, affirmed by a responsible official | CMMC Level 1 and Level 2 (Self); PCI DSS Self-Assessment Questionnaire | ## Attestation in more detail The AICPA's attestation standards (the SSAEs) govern examination, review and agreed-upon procedures engagements. Under them: - the CPA performing an attestation engagement is called a **practitioner**; - in an **examination engagement**, the practitioner expresses an **opinion** on subject matter, or on an assertion about the subject matter, in relation to an identified set of **criteria**; - in a SOC 2 examination, those criteria are the **Trust Services Criteria**, and the practitioner evaluates whether controls were **suitably designed and operated effectively** to meet the entity's service commitments and system requirements. The output is a **report for its intended users**, not a public badge. The reader must read it: the scope, the period, the tested controls and any exceptions are the content. ## Certification in more detail Certification is a **conformity assessment**. For ISO/IEC 27001, an independent certification body audits the information security management system and, if it conforms, issues a certificate that is kept alive by periodic audits over its cycle. The certificate states *that* the organization conforms; it does not publish detailed test results. The CMMC rule shows the same pattern in a government programme: Level 2 (C3PAO) and Level 3 (DIBCAC) are called **certification assessments**, performed by authorized or accredited third parties, and the rule requires the accreditation body to meet ISO/IEC 17011 and to accredit assessment organizations to ISO/IEC 17020. ## Self-assessment in more detail Self-assessment trades independence for cost and speed: - Under **32 CFR 170**, a Level 1 or Level 2 (Self) assessment is performed by the organization, scored and submitted, and a senior official **affirms** compliance at each assessment and annually. - Under **PCI DSS**, eligible entities complete a **Self-Assessment Questionnaire (SAQ)** rather than a Report on Compliance by a Qualified Security Assessor. The affirmation matters (the CMMC rule requires one after certification assessments too, not only self-assessments): a false self-assessment is the signing official's problem, which is why self-assessment is not a lighter duty, only a cheaper process. ## What each tells a customer - A **certificate** says an independent body found conformity with a standard at its last audit. - An **attestation report** says what controls existed, how a practitioner tested them and what exceptions were found, over a stated period or at a point in time. - A **self-assessment** says what the organization concluded about itself, backed by its own official's signature. ## Choosing which to pursue The choice is usually driven by who is asking. Buyers who want to see how controls were tested tend to ask for an attestation report they can read; buyers who want a recognized badge across many markets tend to ask for a certificate; government programmes decide for you, as CMMC does by assigning self-assessment or third-party assessment per contract. Cost, lead time and how much detail the organization is willing to share with customers all enter the decision, and many organizations end up holding more than one. ## Common mistakes - **"SOC 2 certified."** SOC 2 is an attestation; the correct phrase is "we have a SOC 2 report" or "a SOC 2 examination". - **Treating a certificate as proof of every control.** Certification speaks to conformity with the standard's requirements within the certified scope, not to controls outside it. - **Treating self-assessment as optional rigour.** Where a regime allows it, it still carries formal affirmation and consequences for misstatement. A strong answer separates the three by evaluator and output, uses the words *certificate*, *opinion* and *affirmation* correctly, and explains why a buyer might ask for one rather than another.

  • Why can't a company say it is "SOC 2 certified"?
    Because a SOC 2 report is an attestation, not a certification. A CPA practitioner expresses an opinion against the Trust Services Criteria in an examination engagement; no certificate of conformity is issued, and the report is meant for specified users to read.
  • What does an affirmation add to a CMMC self-assessment?
    Under 32 CFR 170, a senior official affirms the organization's compliance at each assessment and annually. It turns the self-assessment into a formal statement the organization stands behind, with consequences if it is wrong.

saying these in an interview costs you the question

  • Calls a SOC 2 report a certification
  • Believes a certificate lists every control tested and its exceptions
  • Treats self-assessment as having no formal accountability
  • Thinks any consultant can issue an ISO/IEC 27001 certificate
  • Says an attestation report is a public seal for anyone to rely on
open as a page

What are the CIS Critical Security Controls v8.1, and how are their 18 Controls and 153 Safeguards meant to be used?

level: juniorimportance: must knowfreq 50%

basics

~20 s

The CIS Controls v8.1 are a prescriptive, prioritized set of 18 security Controls broken into 153 Safeguards. They tell an organization what to do first, starting with asset and software inventory, rather than serving as a certification standard.

open as a page

Under the HIPAA Security Rule, what are the administrative, physical and technical safeguards, and why is the 164.308(a)(1) risk analysis the starting point?

level: juniorimportance: must knowfreq 58%

basics

~20 s

The HIPAA Security Rule protects electronic PHI through administrative (164.308), physical (164.310) and technical (164.312) safeguards. The required risk analysis in 164.308(a)(1) comes first because every choice of reasonable and appropriate measures rests on it.

open as a page

What is the difference between ISO/IEC 27001 and ISO/IEC 27002, and which one can an organization be certified against?

level: juniorimportance: must knowfreq 60%

basics

~20 s

ISO/IEC 27001 states the requirements for an information security management system, including the Annex A control list, and is the standard organizations are certified against. ISO/IEC 27002 is guidance on implementing each of those controls and cannot be certified.

open as a page

What are the six Functions of the NIST Cybersecurity Framework 2.0, and what does the new Govern Function add?

level: juniorimportance: must knowfreq 62%

basics

~20 s

NIST CSF 2.0 organizes outcomes under six Functions: Govern, Identify, Protect, Detect, Respond and Recover. Govern, new in 2.0, covers risk strategy, roles, policy, oversight and supply chain risk, and informs how the other five are implemented.

open as a page

Under PCI DSS v4.0.1, what are the 12 principal requirements, and which account data do they protect?

level: juniorimportance: must knowfreq 60%

basics

~20 s

PCI DSS v4.0.1 has 12 principal requirements under six headings, from network security controls to policy. They protect account data: cardholder data (PAN, name, expiry, service code) and sensitive authentication data, which may not be stored after authorization.

open as a page

In an enterprise security risk register, what does each row record, and why are inherent and residual risk kept separately?

level: juniorimportance: must knowfreq 55%

basics

~20 s

Each row names one risk scenario, its accountable owner, the inherent rating, the controls relied on, the chosen treatment, the residual rating and a review date. Keeping inherent and residual apart shows how much the rating depends on controls working.

open as a page

In the AICPA Trust Services Criteria for SOC 2, what are the five categories, and which criteria apply to every examination?

level: juniorimportance: must knowfreq 55%

basics

~20 s

The categories are security, availability, processing integrity, confidentiality and privacy. The common criteria (CC1 to CC9) apply in every SOC 2 examination; each other category chosen adds its own criteria: A, PI, C or P series.

open as a page

What is the difference between a SOC 2 Type I and a SOC 2 Type II report, and which does an enterprise customer usually want?

level: juniorimportance: must knowfreq 65%

basics

~20 s

A SOC 2 Type I report gives the auditor's opinion on whether controls were suitably designed as of a date. A Type II adds an opinion on operating effectiveness over a period, with the tests and results. Enterprise customers usually want Type II.

open as a page

In a security controls audit, what is the difference between testing a control's design and testing its operating effectiveness?

level: middleimportance: must knowfreq 50%

basics

~20 s

Testing design asks whether a control, as described and placed, would meet its objective if performed. Testing operating effectiveness asks whether it was actually performed as designed, consistently, across the period, which needs evidence from samples over time.

open as a page

A 40-person company with no security team adopts CIS Controls v8.1 — what are Implementation Groups, and why start with IG1?

level: middleimportance: must knowfreq 46%

basics

~20 s

CIS Implementation Groups IG1-IG3 sort the 153 Safeguards by an organization's risk profile and resources. IG1 is essential cyber hygiene, the foundational set every enterprise should apply first; IG2 builds on it and IG3 is all Safeguards.

open as a page

Under the HIPAA Security Rule, a telehealth startup stores patient messages with a cloud provider — is encryption at rest optional because it is 'addressable'?

level: middleimportance: must knowfreq 52%

basics

~20 s

No. Under 45 CFR 164.306(d)(3), an addressable specification such as encryption must be assessed; the startup implements it if reasonable and appropriate, or documents why not and implements an equivalent alternative if that is reasonable and appropriate.

open as a page

In ISO/IEC 27001:2022, what do clauses 4 to 10 require, and why is implementing Annex A controls alone not enough for certification?

level: middleimportance: must knowfreq 55%

basics

~20 s

Clauses 4 to 10 require the management system itself: context and scope, leadership, risk-based planning, support, operation, performance evaluation and improvement. They cannot be excluded, so controls without a working, audited and reviewed ISMS do not conform.

open as a page

In ISO/IEC 27001:2022, what does the Statement of Applicability contain, and how do you justify excluding an Annex A control?

level: middleimportance: must knowfreq 55%

basics

~20 s

The Statement of Applicability lists the necessary controls, why each is included, whether it is implemented, and why any Annex A control is excluded. An exclusion is justified by the risk assessment or scope showing no risk the control would treat.

open as a page

In NIST SP 800-53 Rev. 5, how are controls grouped into families, and how is an SP 800-53B baseline selected and tailored?

level: middleimportance: must knowfreq 50%

basics

~20 s

SP 800-53 Rev. 5 groups its controls into 20 families such as AC, AU and SR. A system's FIPS 199 impact levels, combined by the high water mark, pick the Low, Moderate or High baseline in SP 800-53B, which is then tailored and documented.

open as a page

Under PCI DSS v4.0.1, a call centre takes card numbers by phone: which systems are in scope, and what must segmentation prove?

level: middleimportance: must knowfreq 50%

basics

~20 s

Under PCI DSS v4.0.1, scope covers systems that store, process or transmit card data, anything with unrestricted connectivity to them, and anything that could impact them. Segmentation removes a system only if its compromise could not impact card data.

open as a page

In ISO 27005 and NIST SP 800-53 RA-7 terms, what are the risk treatment options, and who may accept the residual risk?

level: middleimportance: must knowfreq 60%

basics

~20 s

Risk can be mitigated (ISO 27005: modified), transferred or shared, avoided, or accepted (retained). Residual risk may be accepted only by a risk owner with authority to bear it, documented with rationale and a review date.

open as a page

Under the HIPAA Breach Notification Rule, a hospital loses an unencrypted laptop holding 800 patients' records — who must it notify, and by when?

level: seniorimportance: must knowfreq 50%

basics

~20 s

Unless a four-factor risk assessment shows a low probability of compromise, it is a breach of unsecured PHI. The hospital notifies each patient within 60 calendar days of discovery, HHS contemporaneously (500 or more), and media where more than 500 residents of one state are affected.

open as a page

Under PCI DSS v4.0.1, what distinguishes a Self-Assessment Questionnaire from a Report on Compliance, and what does the AOC attest?

level: juniorimportance: should knowfreq 52%

basics

~20 s

Under PCI DSS v4.0.1, an SAQ records an entity's own self-assessment, while a ROC documents a detailed assessment by a QSA or ISA. The AOC is the official PCI SSC form attesting to the results recorded in either.

open as a page

When scoping a security compliance audit, which boundaries must be fixed first, and what goes wrong when one is left vague?

level: middleimportance: should knowfreq 42%

basics

~20 s

An audit's scope fixes the systems and their boundary, the locations, the period or date covered, and the criteria or controls tested. A vague boundary drags in connected systems; a vague period or criteria set leaves the report unable to support the claims customers make.

open as a page

A team replaces spreadsheet evidence with a continuous-compliance platform — what can automated monitoring prove to an auditor, and what can it not?

level: middleimportance: should knowfreq 40%

basics

~20 s

Automated monitoring can show that connected systems met configured checks across the whole population and period. It cannot prove its own coverage is complete, that each check tests what the control says, or that human-judgment controls such as access-review decisions were done well.

open as a page

What is a CIS Benchmark, and how do its Level 1 and Level 2 profiles differ when hardening a Linux server fleet?

level: middleimportance: should knowfreq 44%

basics

~20 s

A CIS Benchmark is a consensus-based set of prescriptive configuration recommendations for one product and version. Level 1 holds practical settings with little functional impact; Level 2 adds defence-in-depth settings for high-security use that may reduce functionality or performance.

open as a page

Under HIPAA, a billing company processes claims for several clinics — is it a business associate, and what must its business associate contracts contain?

level: middleimportance: should knowfreq 48%

basics

~20 s

Yes. Under 45 CFR 160.103 a firm handling PHI on a covered entity's behalf for billing or claims processing is a business associate. Each clinic needs a written contract under 164.308(b) and 164.314(a), and the billing company needs one with each subcontractor.

open as a page

What is HITRUST CSF certification, how do its e1, i1 and r2 assessments differ, and how does it relate to HIPAA compliance?

level: middleimportance: should knowfreq 32%

basics

~20 s

HITRUST CSF is a private control framework harmonizing many standards, including HIPAA. Its e1 (43 controls) and i1 (182 requirements) certifications last one year; the tailored r2 lasts two. None replaces the Security Rule's own duties.

open as a page

A hospital uses NIST CSF 2.0 to report cybersecurity posture to its board — what do Current and Target Profiles and the Tiers each express?

level: middleimportance: should knowfreq 42%

basics

~20 s

Under NIST CSF 2.0, a Current Profile states which Core outcomes the hospital achieves and how far; a Target Profile states the outcomes it has chosen to reach. Tiers 1-4 characterize how rigorous its risk governance and management practices are.

open as a page

Under PCI DSS v4.0.1, how does an online store's choice of hosted payment page, embedded iframe or its own card form change its scope?

level: middleimportance: should knowfreq 42%

basics

~20 s

Under PCI DSS v4.0.1, an own card form puts the store's web stack in the CDE. A hosted page keeps PANs off its servers, though its redirect can still impact security; an iframe also brings Requirements 6.4.3 and 11.6.1 to the surrounding page.

open as a page

Under PCI DSS v4.0.1, a retailer replaces its stored PANs with tokens: which systems can leave scope, and which must stay?

level: middleimportance: should knowfreq 45%

basics

~20 s

Under PCI DSS v4.0.1, systems holding only tokens, unable to detokenize or impact the CDE, can leave scope. The token vault, detokenization paths, systems capturing the PAN before tokenization and anything able to impact them stay in scope.

open as a page

Under NIST SP 800-30 Rev. 1, what are the four steps of a risk assessment, and how does ISO 27005 structure the same work?

level: middleimportance: should knowfreq 40%

basics

~20 s

NIST SP 800-30 Rev. 1 runs prepare, conduct, communicate results and maintain; conducting identifies threat sources, threat events, vulnerabilities, likelihood, impact and finally risk. ISO/IEC 27005 frames the same work as context, identification, analysis, evaluation, treatment and acceptance, with continual monitoring.

open as a page

What is a SOC 2 bridge letter, who issues it, and what assurance does it give an enterprise customer?

level: middleimportance: should knowfreq 35%

basics

~20 s

A SOC 2 bridge letter covers the gap between the end of the last report's period and today. Management of the service organization issues it, stating no material changes or failures; it carries no auditor opinion, so its assurance is limited.

open as a page

In a SOC 2 report, what are complementary user entity controls and subservice organizations, and how do the carve-out and inclusive methods differ?

level: middleimportance: should knowfreq 45%

basics

~20 s

Complementary user entity controls are controls the customer must operate for the vendor's controls to meet the criteria. Subservice organizations are the vendor's own providers; under carve-out their controls are excluded, under the inclusive method they are described and tested in the report.

open as a page

showing 1–30 of 42