Infosec Frameworks & Certification
ISO 27001, SOC 2, NIST, PCI DSS, CIS and HIPAA: the control frameworks security programs are audited against. Interviewers probe whether you can run security through controls, evidence and audits.
part ofCompliance & governance standardsoverview, primer and where to startread it →on this pageshowhide
explore
- Security Risk Management5 questions
- ISO 27001 & 270025 questions
- SOC 25 questions
- NIST CSF & 800-Series5 questions
- PCI DSS6 questions
- HIPAA Security Rule & HITRUST5 questions
- CIS Controls & Hardening Baselines5 questions
- Audit & Attestation Operations6 questions
questions
page 2 of 2A federal cloud system goes to authorization with open assessment findings — what must its plan of action and milestones contain under NIST SP 800-37 and CA-5?
basics
~20 sUnder NIST SP 800-37 task A-6, the plan of action and milestones lists each deficiency's remediation tasks, resources, milestones and scheduled completion dates. The authorizing official reviews it, and control CA-5 requires it to be updated from assessments, audits and continuous monitoring.
In the first year of a SOC 2 Type II audit, one sampled quarterly access review has no evidence — how is the sample handled, and what should the team do?
basics
~20 sThe missing review is an exception: that instance of the control did not operate. The team must not recreate backdated evidence; it discloses the gap, performs the review now with a true date, checks what access changed during the gap and fixes the cause.
Under NIST SP 800-53 controls CM-2 and CM-6, how does a hardening baseline become a documented standard with approved deviations?
basics
~20 sUnder NIST SP 800-53 CM-6 the organization picks a common secure configuration such as a CIS Benchmark, sets the most restrictive settings consistent with operations, and identifies, documents and approves every deviation. CM-2 keeps the resulting baseline current under configuration control.
A defence contractor is told its systems must meet DISA STIGs — how do STIGs differ from CIS Benchmarks, and who must follow each?
basics
~20 sSTIGs are Security Technical Implementation Guides published by the Defense Information Systems Agency for Defense Department systems; CIS Benchmarks are consensus configuration guides anyone may adopt. A contractor follows STIGs because its contract or customer requires them.
In ISO/IEC 27001 certification, what do the stage 1 and stage 2 audits check, and how do nonconformities play out over the three-year cycle?
basics
~20 sStage 1 checks readiness: scope, documents, risk method, Statement of Applicability, and that internal audit and management review have run. Stage 2 checks the ISMS operates effectively. Major nonconformities block certification until closed; minors need an accepted plan. Surveillance audits follow, then recertification.
Under ISO/IEC 27001:2022, how do internal audit and management review show continual improvement, and what does a certification auditor expect to see?
basics
~20 sInternal audit checks at planned intervals, by objective auditors, that the ISMS conforms and works; management review has top management weigh performance, audit results, risks and changes and decide improvements. Auditors expect programmes, records, decisions and closed corrective actions.
Under NIST SP 800-171 Rev. 3 and the CMMC rule (32 CFR part 170), what must a defence subcontractor handling Controlled Unclassified Information demonstrate?
basics
~20 sSP 800-171 sets confidentiality requirements for CUI in nonfederal systems. CMMC is DoD's verification: a subcontractor handling CUI needs at least Level 2, whose 110 requirements are those of SP 800-171 Revision 2, not Revision 3.
Under the NIST RMF (SP 800-37 Rev. 2), how does a federal agency authorize a SaaS vendor's cloud service, and where does FedRAMP fit?
basics
~20 sUnder SP 800-37 Rev. 2, an agency's authorizing official reviews the service's authorization package and accepts the residual risk. For cloud services the agency can issue an authorization to use, relying on a provider authorization such as FedRAMP's instead of reassessing from scratch.
A legacy system cannot meet a PCI DSS v4.0.1 requirement as written: when do you use a compensating control, and when the customized approach?
basics
~20 sUnder PCI DSS v4.0.1, a compensating control answers a documented constraint within the defined approach, via Appendix C's worksheet. The customized approach is a chosen design meeting a requirement's objective, backed by Requirement 12.3.2's targeted risk analysis and ROC validation.
Under NIST CSF 2.0's GV.RM-02, how do risk appetite and risk tolerance differ, and what should happen when a residual risk exceeds tolerance?
basics
~20 sRisk appetite is the broad amount and type of risk leadership is willing to take in pursuit of objectives; risk tolerance turns it into measurable limits. A residual risk beyond tolerance is escalated to whoever owns the appetite, to re-treat or explicitly accept.
Using FAIR quantitative risk analysis, how would you answer a board asking how much a ransomware outage could cost per year?
basics
~20 sFAIR splits the scenario into loss event frequency and loss magnitude, estimates each as a calibrated range, and simulates them into an annual loss distribution. The board gets a median and a severe-year figure, not one number or a colour.
An enterprise customer's procurement team receives a vendor's SOC 2 Type II report: which sections do they read, and when do exceptions or a modified opinion matter?
basics
~20 sRead the auditor's opinion, management's assertion, the system description (scope, categories, subservice organizations, CUECs) and the tests and results. Exceptions matter when they hit controls you rely on; a qualified or adverse opinion means criteria were not met.
showing 31–42 of 42