Cheat sheet

PECB ISO/IEC 27001 Foundation Cheat Sheet

Quick Facts

Exam
PECB Foundation
Provider scope
PECB only
Questions
40 multiple-choice
Options
Three per question
Duration
60 minutes
Pass
70%
Book
Closed book
Domains
Two, weighted 50% each
Standard
2022 + Amd 1:2024
Family overview
ISO/IEC 27000:2026
Training
PECB course required
Education
No academic prerequisite
Experience
None required
Delivery
Online or partner paper-based
Designation
PECB Certificate Holder
First retake
Wait 15 days

CIA Triad

Secret, correct, ready

C: confidentialityI: integrityA: availability

27001 vs 27002

ISO/IEC 27001

  • ISMS requirements
  • Organization certifiable
  • Clauses + Annex A

ISO/IEC 27002

  • Control guidance
  • Not independently certifiable
  • Implementation practices

Requirements vs guidance

ISO Family

ISO/IEC 27000
Concepts + principles + relationships2026
ISO/IEC 27001
Certifiable ISMS requirements
ISO/IEC 27002
Control implementation guidance
ISO/IEC 27003
ISMS implementation guidance
ISO/IEC 27004
Monitoring + measurement guidance
ISO/IEC 27005
Risk management guidance
ISO/IEC 27006-1
Certification-body requirements
ISO/IEC 27007
ISMS auditing guidance

ISMS vs Control

ISMS

  • Management system
  • Risk-based governance
  • Continually improved

Control

  • Risk-modifying measure
  • Specific safeguard
  • Selected as needed

System vs measure

PECB Program Rules

Training
Complete PECB Foundation course
Course formats
Classroom, live online, eLearning, self-study
Exam delivery
Online or partner paper-based
Designation
PECB Certificate Holder
Application
Required after passing exam
Experience
None required
Code of Ethics
Signing required
Language allowance
Ten extra minutes upon request
Online results
Instant after submission
Paper results
Two to four weeks

Threat vs Vulnerability

Threat

  • Potential cause
  • May exploit weakness
  • May cause incident

Vulnerability

  • Existing weakness
  • Can be exploited
  • Raises exposure

Cause vs weakness

Security Properties

Confidentiality
Prevent unauthorized disclosureCIA
Integrity
Preserve accuracy + completenessCIA
Availability
Accessible when requiredCIA
Authenticity
Entity is genuine
Accountability
Actions trace to actors
Non-repudiation
Actions cannot be denied
Reliability
Consistent intended behavior
Information security
Preserve security properties

Risk Concepts

Asset
Something valuable
Threat
Potential incident cause
Vulnerability
Exploitable weakness
Event
Occurrence or circumstance change
Likelihood
Chance of occurrence
Consequence
Outcome affecting objectives
Risk
Uncertainty affecting objectives
Impact
Consequence magnitude
Residual risk
Risk remaining after treatment
Risk owner
Authority + accountability

Cloud + AI

Cloud
Shared configurable resources
Scalability
Expand capacity
Elasticity
Adjust with demand
Shared responsibility
Duties divided
AI
Machine-based inference
Training data
Shapes model behavior
AI risks
Bias + opacity + drift
Cloud risks
Dependency + shared tenancy

Clauses 4-10

Context Leads Planning; Support Operates; Performance Improves

4 Context5 Leadership6 Planning7 Support8 Operation9 Performance10 Improvement

Assessment vs Treatment

Assessment

  • Identify risks
  • Analyze likelihood + consequence
  • Evaluate criteria

Treatment

  • Choose option
  • Select controls
  • Plan actions

Understand vs change

Risk Treatment Picker

  1. Risk needs reductionModify(Apply controls)
  2. Activity can stopAvoid(Remove source)
  3. Another party can bearShare(Contract or insurance)
  4. Risk meets criteriaRetain(Accept knowingly)
  5. Treatment selectedChoose controls(Need-driven)
  6. Controls selectedCompare Annex A(Omission check)
  7. Decisions establishedUpdate SoA(Include reasons + status)
  8. Residual risk remainsOwner approval(Formal acceptance)

Clause Map

Clauses 1-3
Scope, references, terms
Clause 4
Context + ISMS scope
Clause 5
Leadership + policy + roles
Clause 6
Risks + objectives + changes
Clause 7
Support + documented information
Clause 8
Operational planning + control
Clause 9
Performance evaluation
Clause 10
Improvement + corrective action
Annex A
Control reference set

Risk Flow

Identify, analyze, evaluate; treat, then accept

Set criteria firstApprove residual risk

Internal Audit vs Management Review

Internal audit

  • Independent evidence
  • Checks conformity
  • Checks implementation

Management review

  • Top management
  • Strategic evaluation
  • Sets decisions

Assurance vs direction

Clause Picker

  1. Need scope + contextClause 4
  2. Need leadership + policyClause 5
  3. Need risks + objectivesClause 6
  4. Need competence + documentsClause 7
  5. Need operational executionClause 8
  6. Need audits + reviewsClause 9
  7. Need corrections + improvementClause 10
  8. Need control cross-checkAnnex A

Context + Leadership

4.1 Issues
Internal + external context
Climate check
Determine climate relevanceAmd 1
4.2 Parties
Needs + applicable requirements
Climate note
Parties may have requirementsAmd 1
4.3 Scope
Boundaries + applicability
4.4 ISMS
Establish, implement, maintain, improve
5.1 Leadership
Commitment + integration
5.2 Policy
Direction + commitments
5.3 Roles
Responsibilities + authorities

Corrective Flow

React, correct, find cause, act, verify

Control consequencesPrevent recurrenceReview effectiveness

Correction vs Corrective Action

Correction

  • Fix detected issue
  • Immediate response
  • Controls consequence

Corrective action

  • Address root cause
  • Prevent recurrence
  • Review effectiveness

Fix now vs prevent

Assurance Picker

  1. Check own ISMSInternal audit(First party)
  2. Check supplierSupplier audit(Second party)
  3. Certify organizationCertification audit(Third party)
  4. Plan internal auditDefine criteria + scope
  5. Collect audit evidenceSample + verify
  6. Requirement fulfilledConformity
  7. Requirement unfulfilledNonconformity
  8. Need leadership evaluationManagement review(Not an audit)

Risk + Objectives

Risk criteria
Define assessment + acceptance
Assessment
Identify, analyze, evaluate
Treatment
Modify, retain, avoid, share
Necessary controls
Chosen from treatment needs
Annex comparison
Check omitted necessary controls
SoA
Record control decisions + status
Treatment plan
Actions + owners + timing
Residual risk
Risk owner approval
6.2 Objectives
Consistent + monitored + updated
6.3 Changes
Planned manner

Policy vs Objective

Policy

  • High-level direction
  • Commitment framework
  • Supports strategy

Objective

  • Specific intended result
  • Measurable when practicable
  • Monitored + updated

Direction vs result

Support + Operation

7.1 Resources
Enable ISMS operation
7.2 Competence
Education + training + experience
7.3 Awareness
Policy + contribution + consequences
7.4 Communication
What, when, whom, how, who
7.5 Documentation
Create + update + control
8.1 Operations
Plan + implement + control
External processes
Determine + control
8.2 Assessment
Intervals + significant changes
8.3 Treatment
Implement treatment plan

Evaluate + Improve

9.1 Evaluation
What + methods + timing + responsibility
Monitoring
Determine system status
Measurement
Assign values
Analysis
Examine data relationships
Evaluation
Judge against criteria
9.2 Internal audit
Conformity + effective implementation
9.3 Management review
Suitability + adequacy + effectiveness
10.1 Improvement
Continually improve ISMS
10.2 Nonconformity
React + control + correct
Corrective action
Remove causes + prevent recurrence

Annex Counts

O37 + P8 + P14 + T34 = 93

Organizational 37People 8Physical 14Technological 34

Annex A vs SoA

Annex A

  • Reference controls
  • 93-control cross-check
  • Not automatic checklist

SoA

  • Organization-specific record
  • Inclusions + exclusions
  • Implementation status

Reference vs decision record

Annex A Structure

Total
93 controls2022
A.5 Organizational
37 controls
A.6 People
8 controls
A.7 Physical
14 controls
A.8 Technological
34 controls
Purpose
Necessary-control cross-check
Applicability
Risk-driven, not automatic
Custom controls
Allowed when necessary
ISO/IEC 27002
Implementation guidance

Organizational Controls

A.5.1
Security policies
A.5.7
Threat intelligenceNew 2022
A.5.9
Asset inventory
A.5.15
Access control
A.5.19
Supplier security
A.5.23
Cloud service securityNew 2022
A.5.24
Incident preparation
A.5.29
Security during disruption
A.5.30
ICT continuity readinessNew 2022
A.5.31
Legal + contractual requirements
A.5.37
Operating procedures

People + Physical

A.6.1
Personnel screening
A.6.2
Employment terms
A.6.3
Awareness + training
A.6.5
Post-employment duties
A.6.7
Remote working
A.6.8
Event reporting
A.7.1
Physical perimeters
A.7.2
Physical entry
A.7.4
Physical monitoringNew 2022
A.7.5
Environmental threats
A.7.9
Off-premises assets
A.7.10
Storage media
A.7.14
Secure disposal + reuse

Technological Controls

A.8.1
Endpoint devices
A.8.2
Privileged access
A.8.5
Secure authentication
A.8.7
Malware protection
A.8.8
Vulnerability management
A.8.9
Configuration managementNew 2022
A.8.10
Information deletionNew 2022
A.8.11
Data maskingNew 2022
A.8.12
Data leakage preventionNew 2022
A.8.13
Information backup
A.8.15
Logging
A.8.16
Monitoring activitiesNew 2022
A.8.20
Network security
A.8.24
Cryptography
A.8.25
Secure development lifecycle
A.8.28
Secure codingNew 2022

Common Traps

Provider identity

PECB rules apply here Not universal ISO rules

Training vs experience

PECB course required Experience not required

Holder vs certified

Official status: Certificate Holder Not occupational certification or licensure

Current ISO/IEC 27000

2026 edition is current Not primarily terminology anymore

Annex A usage

Reference set Not automatically all applicable

Control universe

Necessary controls may differ Annex comparison still required

Residual risk

Risk owner accepts Auditor does not accept

Audit vs review

Audit gives assurance Management review directs

Certification meaning

ISMS conformity Not flawless security

Documentation myth

Required evidence documented Not every process needs procedure

Last Minute

  1. 1.PECB: 40 questions, 60 minutes
  2. 2.PECB: 70%; closed book
  3. 3.Official domains: 50% + 50%
  4. 4.2022 plus Amd 1:2024
  5. 5.ISO/IEC 27000 current = 2026
  6. 6.Training required; no academic prerequisite
  7. 7.Online or partner paper-based exam
  8. 8.Designation: PECB Certificate Holder
  9. 9.Clauses 4-10 are requirements
  10. 10.Annex A total = 93
  11. 11.27001 requirements; 27002 guidance
  12. 12.Risk: identify, analyze, evaluate, treat
  13. 13.SoA records control decisions
  14. 14.Residual risk needs owner approval
  15. 15.Internal audit differs management review
  16. 16.Correction fixes; corrective action prevents
  17. 17.Climate relevance belongs in context
  18. 18.PECB rules are not ISO-wide
Same family resources

Explore More PECB Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.