skip to content

Infosec Frameworks & Certification

ISO 27001, SOC 2, NIST, PCI DSS, CIS and HIPAA: the control frameworks security programs are audited against. Interviewers probe whether you can run security through controls, evidence and audits.

part ofCompliance & governance standardsoverview, primer and where to startread it →
on this pageshow

explore

questions

page 2 of 2

A federal cloud system goes to authorization with open assessment findings — what must its plan of action and milestones contain under NIST SP 800-37 and CA-5?

level: seniorimportance: should knowfreq 36%

basics

~20 s

Under NIST SP 800-37 task A-6, the plan of action and milestones lists each deficiency's remediation tasks, resources, milestones and scheduled completion dates. The authorizing official reviews it, and control CA-5 requires it to be updated from assessments, audits and continuous monitoring.

open as a page

In the first year of a SOC 2 Type II audit, one sampled quarterly access review has no evidence — how is the sample handled, and what should the team do?

level: seniorimportance: should knowfreq 45%

basics

~20 s

The missing review is an exception: that instance of the control did not operate. The team must not recreate backdated evidence; it discloses the gap, performs the review now with a true date, checks what access changed during the gap and fixes the cause.

open as a page

Under NIST SP 800-53 controls CM-2 and CM-6, how does a hardening baseline become a documented standard with approved deviations?

level: seniorimportance: should knowfreq 36%

basics

~20 s

Under NIST SP 800-53 CM-6 the organization picks a common secure configuration such as a CIS Benchmark, sets the most restrictive settings consistent with operations, and identifies, documents and approves every deviation. CM-2 keeps the resulting baseline current under configuration control.

open as a page

A defence contractor is told its systems must meet DISA STIGs — how do STIGs differ from CIS Benchmarks, and who must follow each?

level: seniorimportance: should knowfreq 34%

basics

~20 s

STIGs are Security Technical Implementation Guides published by the Defense Information Systems Agency for Defense Department systems; CIS Benchmarks are consensus configuration guides anyone may adopt. A contractor follows STIGs because its contract or customer requires them.

open as a page

In ISO/IEC 27001 certification, what do the stage 1 and stage 2 audits check, and how do nonconformities play out over the three-year cycle?

level: seniorimportance: should knowfreq 45%

basics

~20 s

Stage 1 checks readiness: scope, documents, risk method, Statement of Applicability, and that internal audit and management review have run. Stage 2 checks the ISMS operates effectively. Major nonconformities block certification until closed; minors need an accepted plan. Surveillance audits follow, then recertification.

open as a page

Under ISO/IEC 27001:2022, how do internal audit and management review show continual improvement, and what does a certification auditor expect to see?

level: seniorimportance: should knowfreq 35%

basics

~20 s

Internal audit checks at planned intervals, by objective auditors, that the ISMS conforms and works; management review has top management weigh performance, audit results, risks and changes and decide improvements. Auditors expect programmes, records, decisions and closed corrective actions.

open as a page

Under NIST SP 800-171 Rev. 3 and the CMMC rule (32 CFR part 170), what must a defence subcontractor handling Controlled Unclassified Information demonstrate?

level: seniorimportance: should knowfreq 34%

basics

~20 s

SP 800-171 sets confidentiality requirements for CUI in nonfederal systems. CMMC is DoD's verification: a subcontractor handling CUI needs at least Level 2, whose 110 requirements are those of SP 800-171 Revision 2, not Revision 3.

open as a page

Under the NIST RMF (SP 800-37 Rev. 2), how does a federal agency authorize a SaaS vendor's cloud service, and where does FedRAMP fit?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Under SP 800-37 Rev. 2, an agency's authorizing official reviews the service's authorization package and accepts the residual risk. For cloud services the agency can issue an authorization to use, relying on a provider authorization such as FedRAMP's instead of reassessing from scratch.

open as a page

A legacy system cannot meet a PCI DSS v4.0.1 requirement as written: when do you use a compensating control, and when the customized approach?

level: seniorimportance: should knowfreq 33%

basics

~20 s

Under PCI DSS v4.0.1, a compensating control answers a documented constraint within the defined approach, via Appendix C's worksheet. The customized approach is a chosen design meeting a requirement's objective, backed by Requirement 12.3.2's targeted risk analysis and ROC validation.

open as a page

Under NIST CSF 2.0's GV.RM-02, how do risk appetite and risk tolerance differ, and what should happen when a residual risk exceeds tolerance?

level: seniorimportance: should knowfreq 30%

basics

~20 s

Risk appetite is the broad amount and type of risk leadership is willing to take in pursuit of objectives; risk tolerance turns it into measurable limits. A residual risk beyond tolerance is escalated to whoever owns the appetite, to re-treat or explicitly accept.

open as a page

Using FAIR quantitative risk analysis, how would you answer a board asking how much a ransomware outage could cost per year?

level: seniorimportance: should knowfreq 35%

basics

~20 s

FAIR splits the scenario into loss event frequency and loss magnitude, estimates each as a calibrated range, and simulates them into an annual loss distribution. The board gets a median and a severe-year figure, not one number or a colour.

open as a page

An enterprise customer's procurement team receives a vendor's SOC 2 Type II report: which sections do they read, and when do exceptions or a modified opinion matter?

level: seniorimportance: should knowfreq 40%

basics

~20 s

Read the auditor's opinion, management's assertion, the system description (scope, categories, subservice organizations, CUECs) and the tests and results. Exceptions matter when they hit controls you rely on; a qualified or adverse opinion means criteria were not met.

open as a page

showing 31–42 of 42