ISFS · Question #88
Security controls shall be documented. What will the controls be related to?
The correct answer is B. risks. Security controls exist to mitigate risks - they are documented in relation to the specific risks they address, which is a foundational principle in frameworks like ISO 27001 and NIST. This traceability ensures every control can be justified by a corresponding risk, making…
Question
Security controls shall be documented. What will the controls be related to?
Options
- Alocations
- Brisks
- Cservices
- Dstaff
How the community answered
(39 responses)- A5% (2)
- B90% (35)
- C3% (1)
- D3% (1)
Explanation
Security controls exist to mitigate risks - they are documented in relation to the specific risks they address, which is a foundational principle in frameworks like ISO 27001 and NIST. This traceability ensures every control can be justified by a corresponding risk, making audits and reviews coherent.
- A (locations) is wrong because physical locations may influence which controls apply, but controls are not documented in relation to locations.
- C (services) is wrong because services are assets that may be protected by controls, but the documentation rationale is risk-based, not service-based.
- D (staff) is wrong because staff may own or operate controls, but responsibility assignment is separate from the documentation of what a control addresses.
Memory tip: Think of the risk management cycle - identify risk → implement control → document the link. Controls are always the answer to a risk, so they're documented in relation to Risks (B = Right).
Topics
Community Discussion
No community discussion yet for this question.