Domain 1 — ISMS Fundamentals
50%of exam
Domain 2 — ISMS Requirements
50%of exam
Annex A Reference Set
Not publishedof exam
Quick Facts
- Exam
- PECB Foundation
- Provider scope
- PECB only
- Questions
- 40 multiple-choice
- Options
- Three per question
- Duration
- 60 minutes
- Pass
- 70%
- Book
- Closed book
- Domains
- Two, weighted 50% each
- Standard
- 2022 + Amd 1:2024
- Family overview
- ISO/IEC 27000:2026
- Training
- PECB course required
- Education
- No academic prerequisite
- Experience
- None required
- Delivery
- Online or partner paper-based
- Designation
- PECB Certificate Holder
- First retake
- Wait 15 days
CIA Triad
Secret, correct, ready
27001 vs 27002
ISO/IEC 27001
- ISMS requirements
- Organization certifiable
- Clauses + Annex A
ISO/IEC 27002
- Control guidance
- Not independently certifiable
- Implementation practices
Requirements vs guidance
ISO Family
- ISO/IEC 27000
- Concepts + principles + relationships2026
- ISO/IEC 27001
- Certifiable ISMS requirements
- ISO/IEC 27002
- Control implementation guidance
- ISO/IEC 27003
- ISMS implementation guidance
- ISO/IEC 27004
- Monitoring + measurement guidance
- ISO/IEC 27005
- Risk management guidance
- ISO/IEC 27006-1
- Certification-body requirements
- ISO/IEC 27007
- ISMS auditing guidance
ISMS vs Control
ISMS
- Management system
- Risk-based governance
- Continually improved
Control
- Risk-modifying measure
- Specific safeguard
- Selected as needed
System vs measure
PECB Program Rules
- Training
- Complete PECB Foundation course
- Course formats
- Classroom, live online, eLearning, self-study
- Exam delivery
- Online or partner paper-based
- Designation
- PECB Certificate Holder
- Application
- Required after passing exam
- Experience
- None required
- Code of Ethics
- Signing required
- Language allowance
- Ten extra minutes upon request
- Online results
- Instant after submission
- Paper results
- Two to four weeks
Threat vs Vulnerability
Threat
- Potential cause
- May exploit weakness
- May cause incident
Vulnerability
- Existing weakness
- Can be exploited
- Raises exposure
Cause vs weakness
Security Properties
- Confidentiality
- Prevent unauthorized disclosureCIA
- Integrity
- Preserve accuracy + completenessCIA
- Availability
- Accessible when requiredCIA
- Authenticity
- Entity is genuine
- Accountability
- Actions trace to actors
- Non-repudiation
- Actions cannot be denied
- Reliability
- Consistent intended behavior
- Information security
- Preserve security properties
Risk Concepts
- Asset
- Something valuable
- Threat
- Potential incident cause
- Vulnerability
- Exploitable weakness
- Event
- Occurrence or circumstance change
- Likelihood
- Chance of occurrence
- Consequence
- Outcome affecting objectives
- Risk
- Uncertainty affecting objectives
- Impact
- Consequence magnitude
- Residual risk
- Risk remaining after treatment
- Risk owner
- Authority + accountability
Cloud + AI
- Cloud
- Shared configurable resources
- Scalability
- Expand capacity
- Elasticity
- Adjust with demand
- Shared responsibility
- Duties divided
- AI
- Machine-based inference
- Training data
- Shapes model behavior
- AI risks
- Bias + opacity + drift
- Cloud risks
- Dependency + shared tenancy
Clauses 4-10
Context Leads Planning; Support Operates; Performance Improves
Assessment vs Treatment
Assessment
- Identify risks
- Analyze likelihood + consequence
- Evaluate criteria
Treatment
- Choose option
- Select controls
- Plan actions
Understand vs change
Risk Treatment Picker
- Risk needs reduction→Modify(Apply controls)
- Activity can stop→Avoid(Remove source)
- Another party can bear→Share(Contract or insurance)
- Risk meets criteria→Retain(Accept knowingly)
- Treatment selected→Choose controls(Need-driven)
- Controls selected→Compare Annex A(Omission check)
- Decisions established→Update SoA(Include reasons + status)
- Residual risk remains→Owner approval(Formal acceptance)
Clause Map
- Clauses 1-3
- Scope, references, terms
- Clause 4
- Context + ISMS scope
- Clause 5
- Leadership + policy + roles
- Clause 6
- Risks + objectives + changes
- Clause 7
- Support + documented information
- Clause 8
- Operational planning + control
- Clause 9
- Performance evaluation
- Clause 10
- Improvement + corrective action
- Annex A
- Control reference set
Risk Flow
Identify, analyze, evaluate; treat, then accept
Internal Audit vs Management Review
Internal audit
- Independent evidence
- Checks conformity
- Checks implementation
Management review
- Top management
- Strategic evaluation
- Sets decisions
Assurance vs direction
Clause Picker
- Need scope + context→Clause 4
- Need leadership + policy→Clause 5
- Need risks + objectives→Clause 6
- Need competence + documents→Clause 7
- Need operational execution→Clause 8
- Need audits + reviews→Clause 9
- Need corrections + improvement→Clause 10
- Need control cross-check→Annex A
Context + Leadership
- 4.1 Issues
- Internal + external context
- Climate check
- Determine climate relevanceAmd 1
- 4.2 Parties
- Needs + applicable requirements
- Climate note
- Parties may have requirementsAmd 1
- 4.3 Scope
- Boundaries + applicability
- 4.4 ISMS
- Establish, implement, maintain, improve
- 5.1 Leadership
- Commitment + integration
- 5.2 Policy
- Direction + commitments
- 5.3 Roles
- Responsibilities + authorities
Corrective Flow
React, correct, find cause, act, verify
Correction vs Corrective Action
Correction
- Fix detected issue
- Immediate response
- Controls consequence
Corrective action
- Address root cause
- Prevent recurrence
- Review effectiveness
Fix now vs prevent
Assurance Picker
- Check own ISMS→Internal audit(First party)
- Check supplier→Supplier audit(Second party)
- Certify organization→Certification audit(Third party)
- Plan internal audit→Define criteria + scope
- Collect audit evidence→Sample + verify
- Requirement fulfilled→Conformity
- Requirement unfulfilled→Nonconformity
- Need leadership evaluation→Management review(Not an audit)
Risk + Objectives
- Risk criteria
- Define assessment + acceptance
- Assessment
- Identify, analyze, evaluate
- Treatment
- Modify, retain, avoid, share
- Necessary controls
- Chosen from treatment needs
- Annex comparison
- Check omitted necessary controls
- SoA
- Record control decisions + status
- Treatment plan
- Actions + owners + timing
- Residual risk
- Risk owner approval
- 6.2 Objectives
- Consistent + monitored + updated
- 6.3 Changes
- Planned manner
Policy vs Objective
Policy
- High-level direction
- Commitment framework
- Supports strategy
Objective
- Specific intended result
- Measurable when practicable
- Monitored + updated
Direction vs result
Support + Operation
- 7.1 Resources
- Enable ISMS operation
- 7.2 Competence
- Education + training + experience
- 7.3 Awareness
- Policy + contribution + consequences
- 7.4 Communication
- What, when, whom, how, who
- 7.5 Documentation
- Create + update + control
- 8.1 Operations
- Plan + implement + control
- External processes
- Determine + control
- 8.2 Assessment
- Intervals + significant changes
- 8.3 Treatment
- Implement treatment plan
Evaluate + Improve
- 9.1 Evaluation
- What + methods + timing + responsibility
- Monitoring
- Determine system status
- Measurement
- Assign values
- Analysis
- Examine data relationships
- Evaluation
- Judge against criteria
- 9.2 Internal audit
- Conformity + effective implementation
- 9.3 Management review
- Suitability + adequacy + effectiveness
- 10.1 Improvement
- Continually improve ISMS
- 10.2 Nonconformity
- React + control + correct
- Corrective action
- Remove causes + prevent recurrence
Annex Counts
O37 + P8 + P14 + T34 = 93
Annex A vs SoA
Annex A
- Reference controls
- 93-control cross-check
- Not automatic checklist
SoA
- Organization-specific record
- Inclusions + exclusions
- Implementation status
Reference vs decision record
Annex A Structure
- Total
- 93 controls2022
- A.5 Organizational
- 37 controls
- A.6 People
- 8 controls
- A.7 Physical
- 14 controls
- A.8 Technological
- 34 controls
- Purpose
- Necessary-control cross-check
- Applicability
- Risk-driven, not automatic
- Custom controls
- Allowed when necessary
- ISO/IEC 27002
- Implementation guidance
Organizational Controls
- A.5.1
- Security policies
- A.5.7
- Threat intelligenceNew 2022
- A.5.9
- Asset inventory
- A.5.15
- Access control
- A.5.19
- Supplier security
- A.5.23
- Cloud service securityNew 2022
- A.5.24
- Incident preparation
- A.5.29
- Security during disruption
- A.5.30
- ICT continuity readinessNew 2022
- A.5.31
- Legal + contractual requirements
- A.5.37
- Operating procedures
People + Physical
- A.6.1
- Personnel screening
- A.6.2
- Employment terms
- A.6.3
- Awareness + training
- A.6.5
- Post-employment duties
- A.6.7
- Remote working
- A.6.8
- Event reporting
- A.7.1
- Physical perimeters
- A.7.2
- Physical entry
- A.7.4
- Physical monitoringNew 2022
- A.7.5
- Environmental threats
- A.7.9
- Off-premises assets
- A.7.10
- Storage media
- A.7.14
- Secure disposal + reuse
Technological Controls
- A.8.1
- Endpoint devices
- A.8.2
- Privileged access
- A.8.5
- Secure authentication
- A.8.7
- Malware protection
- A.8.8
- Vulnerability management
- A.8.9
- Configuration managementNew 2022
- A.8.10
- Information deletionNew 2022
- A.8.11
- Data maskingNew 2022
- A.8.12
- Data leakage preventionNew 2022
- A.8.13
- Information backup
- A.8.15
- Logging
- A.8.16
- Monitoring activitiesNew 2022
- A.8.20
- Network security
- A.8.24
- Cryptography
- A.8.25
- Secure development lifecycle
- A.8.28
- Secure codingNew 2022
Common Traps
Provider identity
PECB rules apply here ≠ Not universal ISO rules
Training vs experience
PECB course required ≠ Experience not required
Holder vs certified
Official status: Certificate Holder ≠ Not occupational certification or licensure
Current ISO/IEC 27000
2026 edition is current ≠ Not primarily terminology anymore
Annex A usage
Reference set ≠ Not automatically all applicable
Control universe
Necessary controls may differ ≠ Annex comparison still required
Residual risk
Risk owner accepts ≠ Auditor does not accept
Audit vs review
Audit gives assurance ≠ Management review directs
Certification meaning
ISMS conformity ≠ Not flawless security
Documentation myth
Required evidence documented ≠ Not every process needs procedure
Last Minute
- 1.PECB: 40 questions, 60 minutes
- 2.PECB: 70%; closed book
- 3.Official domains: 50% + 50%
- 4.2022 plus Amd 1:2024
- 5.ISO/IEC 27000 current = 2026
- 6.Training required; no academic prerequisite
- 7.Online or partner paper-based exam
- 8.Designation: PECB Certificate Holder
- 9.Clauses 4-10 are requirements
- 10.Annex A total = 93
- 11.27001 requirements; 27002 guidance
- 12.Risk: identify, analyze, evaluate, treat
- 13.SoA records control decisions
- 14.Residual risk needs owner approval
- 15.Internal audit differs management review
- 16.Correction fixes; corrective action prevents
- 17.Climate relevance belongs in context
- 18.PECB rules are not ISO-wide
Explore More PECB Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.