nerdexam
PECB

LEAD-AUDITOR · Question #349

Drag and Drop Question You are an experienced ISMS internal auditor. You have just completed a scheduled information security audit of your organisation when the IT Manager approaches you and asks for

The correct answer is Technological control; Physical control; Organizational control; People control. Issue: Incomplete Question The question as provided is missing the critical content - the specific ISO/IEC 27001 controls that need to be categorized are not included. The question says "He asks you which of the four control categories each of the following should appear under,"

ISO/IEC 27001 Controls Management

Question

Drag and Drop Question You are an experienced ISMS internal auditor. You have just completed a scheduled information security audit of your organisation when the IT Manager approaches you and asks for your assistance in the revision of the company's Statement of Applicability. The IT Manager is attempting to update the ISO/IEC 27001:2013 based Statement of Applicability to a Statement aligned to the 4 control themes present in ISO/IEC 27001:2022 (Organizational controls, People Controls, Physical Controls, Technical Controls). The IT Manager is happy with their reassignment of controls, with the following exceptions. He asks you which of the four control categories each of the following should appear under. Answer:

Exhibit

LEAD-AUDITOR question #349 exhibit

Answer Area

Drag items

Technological controlPeople controlOrganizational controlPhysical control

Correct arrangement

  • Technological control
  • Physical control
  • Organizational control
  • People control

Explanation

Issue: Incomplete Question

The question as provided is missing the critical content - the specific ISO/IEC 27001 controls that need to be categorized are not included. The question says "He asks you which of the four control categories each of the following should appear under," but "the following" controls were never listed.

What you've shared are only the answer options (the four category labels), not the actual controls being sorted.


What I Can Give You: The ISO/IEC 27001:2022 Control Theme Framework

To answer this type of question correctly, use these definitions:

ThemeAnnex A Clause# of ControlsNature
Organizational537Policies, processes, roles, responsibilities, governance
People68Human behavior, awareness, training, HR lifecycle
Physical714Physical premises, hardware, environment
Technological834IT systems, software, networks, cryptography

Quick decision rules:

  • Organizational → Does it involve a policy, procedure, or management decision? → Organizational
  • People → Does it involve a person's behavior, awareness, or employment status? → People
  • Physical → Does it involve a building, room, cable, or device you can touch? → Physical
  • Technological → Does it involve software, systems, networks, or data processing? → Technological

Please share the actual 4 controls listed in the original question and I'll explain exactly why each maps to its category.

Topics

#ISO 27001:2022 controls#control categories#Statement of Applicability#control themes

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice