Mapping ISO 27001-2022 controls to NIST CSF subcategories

Mapping ISO 27001-2022 controls to NIST CSF subcategories

Assessment

Interactive Video

Information Technology (IT), Architecture, Social Studies

University

Hard

Created by

Quizizz Content

FREE Resource

The video tutorial explains the ISO 27001:2022 Annex A controls and their role in enhancing an organization's cybersecurity posture. It provides a detailed mapping between the framework and the standard, emphasizing the need for customization to meet specific organizational needs. The tutorial introduces key abbreviations for functions and categories, and demonstrates how to map controls to subcategories using a provided Excel sheet. An example of mapping cybersecurity roles and responsibilities is given, showing the transition from the 2013 to the 2022 standard.

Read more

5 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What is the primary purpose of ISO 27001:2022 Annex A controls?

To provide a one-size-fits-all solution

To eliminate the need for any customization

To enhance an organization's overall cybersecurity posture

To replace all existing cybersecurity frameworks

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which function abbreviation corresponds to 'Protect'?

ID

PR

RS

DE

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

How is the asset management category abbreviated?

ID.AM

PR.DS

ID.VE

RC.AM

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What does the subcategory ID.AM-1 represent?

Data security

Incident response

Business environment

Asset management

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Which control does ID.AM-6 map to in the 2022 standard?

Control 5.2

Control B2.1

Control A6.1.1

Control 4.3