ISO 27001 Practice Question: The control for access control policy requires: | CyberCertPrep
ISOISO 27001Iso Annex A ControlsEASYFree question
The control for access control policy requires:
A.Access only for IT staff. Annex A control 7.14 applies this requirement to external auditors during the Plan phase.
B.Unrestricted access to all systems
C.An access control policy based on business and information security requirements
D.No access controls for internal networks. This corresponds to Annex A control 5.11 under the 2022 structure, with a different numbering under the 2013 Annex A.
Why C is correct
The access control policy must be established based on business and information security requirements to restrict access appropriately.
Know someone studying for ISO 27001? Send them this one.
Where this fits in the ISO 27001 exam
Iso Annex A Controls
ISO/IEC 27001:2022 Annex A controls: the 93 controls across organizational, people, physical, and technological themes.
This question belongs to the "Annex A Controls" domain, which makes up about 25% of the ISO 27001 exam.
CyberCertPrep gives you 20 free ISO 27001 questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
ISO 27001 and ISO are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by ISO or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
Which Annex A control requires the organization to define an information security policy?