ISO-IEC-27001-LEAD-AUDITOR · Question #150
Drag and Drop Question You are an experienced ISMS internal auditor. You have just completed a scheduled information security audit of your organisation when the IT Manager approaches you and asks…
The correct answer is Technological control; Physical control; Organizational control; People control. Issue with the Question as Presented The question as shared appears to be incomplete. The specific ISO 27001 controls the IT Manager was struggling to categorize (the actual drag items) are missing - only the four category labels appear as both the Available Items and the…
Question
Drag and Drop Question You are an experienced ISMS internal auditor. You have just completed a scheduled information security audit of your organisation when the IT Manager approaches you and asks for your assistance in the revision of the company's Statement of Applicability. The IT Manager is attempting to update the ISO/IEC 27001:2013 based Statement of Applicability to a Statement aligned to the 4 control themes present in ISO/IEC 27001:2022 (Organizational controls, People Controls, Physical Controls, Technical Controls). The IT Manager is happy with their reassignment of controls, with the following exceptions. He asks you which of the four control categories each of the following should appear under. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- Technological control
- Physical control
- Organizational control
- People control
Explanation
Issue with the Question as Presented
The question as shared appears to be incomplete. The specific ISO 27001 controls the IT Manager was struggling to categorize (the actual drag items) are missing - only the four category labels appear as both the Available Items and the Correct Arrangement. Without knowing what controls are being mapped, it's not possible to explain why item 1 maps to "Technological," item 2 to "Physical," etc.
That said, here is a thorough explanation of the underlying framework so you can apply it to whatever specific controls the full question includes.
ISO/IEC 27001:2022 - The Four Control Themes (Annex A)
How They're Ordered in the Standard
| Annex | Theme | Control Count |
|---|---|---|
| A.5 | Organizational | 37 |
| A.6 | People | 8 |
| A.7 | Physical | 14 |
| A.8 | Technological | 34 |
How to Categorize a Control - Decision Logic
Organizational Controls (A.5)
- Govern policies, processes, rules, and responsibilities at the management/governance level
- Examples: Information security policies (A.5.1), Acceptable use (A.5.10), Supplier relationships (A.5.19), Incident management (A.5.24)
- Key test: "Does this exist primarily as a policy, procedure, or structural decision?"
People Controls (A.6)
- Govern human behaviour, awareness, and employment lifecycle
- Examples: Screening (A.6.1), Terms of employment (A.6.2), Security training (A.6.3), Disciplinary process (A.6.4), Remote working (A.6.7)
- Key test: "Does this apply to individuals and their conduct/status?"
Physical Controls (A.7)
- Govern physical access, environment, and tangible asset protection
- Examples: Physical security perimeters (A.7.1), Clear desk/screen (A.7.7), Equipment security (A.7.8), Secure disposal (A.7.14)
- Key test: "Could you touch or physically interact with what this control protects or restricts?"
Technological Controls (A.8)
- Govern IT systems, software, networks, and technical configurations
- Examples: User endpoint devices (A.8.1), Privileged access (A.8.2), Malware protection (A.8.7), Cryptography (A.8.24), SIEM/monitoring (A.8.16)
- Key test: "Is this implemented via a system, tool, or technical configuration?"
Common Mistakes and Misconceptions
1. Confusing "clear desk/clear screen" placement Clear desk is Physical (A.7.7); clear screen could feel technical but is classified as physical because it concerns the physical workspace environment.
2. Assuming "remote working" is Technological Remote working (A.6.7) is a People control - it governs the rules and conditions for people working remotely, not the VPN or encryption used to do so (those would be Technological).
3. Mixing up Organizational vs. People Policies about people (hiring, training, disciplinary procedures) are People controls. Policies about governance, risk, and process structure are Organizational controls.
4. Mapping 2013 controls 1:1 to 2022 The 2022 revision merged, split, and renamed many controls. For example, the old A.12 (Operations security) controls now map across both Organizational (A.5) and Technological (A.8) themes depending on whether they're procedural or technical in nature.
5. Forgetting that one 2013 control can split into multiple 2022 themes The SOA update isn't always a 1:1 remap - a 2013 control may need to be represented under two different 2022 themes.
If you can share the specific controls the IT Manager was uncertain about, I can give you the exact reasoning for each placement.
Topics
Community Discussion
No community discussion yet for this question.
