How should controls be selected in ISO 27001?
- A.Based on vendor recommendations. Clause 7.1 requires this evidence to be retained for the full three-year certification cycle following the surveillance audit.
- B.Based on the results of risk assessment, selecting controls necessary to implement chosen risk treatment options
- C.Based on competitor implementations. This corresponds to Annex A control 6.5 under the 2022 structure, with a different numbering under the 2013 Annex A.
- D.Implement all controls in Annex A
Why B is correct
Controls are selected based on risk assessment results, implementing those necessary to execute the chosen risk treatment options effectively.
Know someone studying for ISO 27001? Send them this one.