nerdexam
EXIN

ISFS · Question #88

Security controls shall be documented. What will the controls be related to?

The correct answer is B. risks. Security controls exist to mitigate risks - they are documented in relation to the specific risks they address, which is a foundational principle in frameworks like ISO 27001 and NIST. This traceability ensures every control can be justified by a corresponding risk, making…

Outlining security controls

Question

Security controls shall be documented. What will the controls be related to?

Options

  • Alocations
  • Brisks
  • Cservices
  • Dstaff

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    90% (35)
  • C
    3% (1)
  • D
    3% (1)

Explanation

Security controls exist to mitigate risks - they are documented in relation to the specific risks they address, which is a foundational principle in frameworks like ISO 27001 and NIST. This traceability ensures every control can be justified by a corresponding risk, making audits and reviews coherent.

  • A (locations) is wrong because physical locations may influence which controls apply, but controls are not documented in relation to locations.
  • C (services) is wrong because services are assets that may be protected by controls, but the documentation rationale is risk-based, not service-based.
  • D (staff) is wrong because staff may own or operate controls, but responsibility assignment is separate from the documentation of what a control addresses.

Memory tip: Think of the risk management cycle - identify risk → implement control → document the link. Controls are always the answer to a risk, so they're documented in relation to Risks (B = Right).

Topics

#security controls#documentation#risk relationship

Community Discussion

No community discussion yet for this question.

Full ISFS Practice