‹ Shelves / IT security ■ GRC + ISO 27001 — certification prepGovernance, risk and compliance, then ISO/IEC 27001:2022 clause by clause and the road to the certificate — with NIS2, DORA, CRA and the AI Act as of 2026. Every lesson has a quiz.
26 lessons · 39 min
The reading track 26 lessons All With quiz · 26 All authors ISO/IEC · 8 Parlamentul European și Consiliul Uniunii Europene · 4 National Institute of Standards and Technology (NIST) · 2 ISO · 2
01 GRC is not a department but the name for integrating governance, risk and compliance; kept apart, the three duplicate and contradict each other. What Is GRC (Governance, Risk, and Compliance)? · OCEG (Open Compliance and Ethics Group) · 2002 ✓ Quiz · 3 questions › 02 In 2024 the NIST framework promoted governance to a function of its own and placed it at the centre: it decides how the other five are applied. The NIST Cybersecurity Framework (CSF) 2.0 · National Institute of Standards and Technology (NIST) · 2024 ✓ Quiz · 3 questions › 03 Risk is measured against objectives, and whoever lacks a named owner for each risk has a spreadsheet, not risk management. Guide for Conducting Risk Assessments (NIST SP 800-30 Rev. 1) · National Institute of Standards and Technology (NIST) · 2012 ✓ Quiz · 3 questions › 04 A certificate says that, on the audit date, a sample of evidence matched the requirements; it says nothing about the next day. The Process of Security · Bruce Schneier · 2000 ✓ Quiz · 3 questions › 05 The three lines are not hierarchical floors but concurrent roles; the rule holding them together is that nobody assures their own work. The IIA's Three Lines Model: An Update of the Three Lines of Defense · The Institute of Internal Auditors (IIA) · 2020 ✓ Quiz · 3 questions › 06 Clause 9.1 does not ask for numbers but for a measurement plan: what, by which method, when and who — then who analyses the results. Electrical Units of Measurement · William Thomson (Lord Kelvin) · 1883 ✓ Quiz · 3 questions › 07 Documented information does not exist for the paper but because one's own memory is the most indulgent auditor anyone has. Cargo Cult Science · Richard P. Feynman · 1974 ✓ Quiz · 3 questions › 08 An ISMS is not a list of controls but the machinery that decides which controls are needed, puts them to work and checks whether they still fit. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · ISO/IEC · 2022 ✓ Quiz · 3 questions › 09 The scope is the only sentence a customer reads and the first page an auditor reads; it must survive both readings. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · ISO/IEC · 2022 ✓ Quiz · 3 questions › 10 Clause 5 does not ask for a security department but for evidence that the people who decide the budget actually run the system: policy, objectives, resources, roles. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · ISO/IEC · 2022 ✓ Quiz · 3 questions › 11 Risk assessment does not produce a list of fears but a comparison against criteria written in advance, which someone else can redo and get the same answer. ISO/IEC 27005:2022 — Information security, cybersecurity and privacy protection — Guidance on managing information security risks · ISO/IEC · 2022 ✓ Quiz · 3 questions › 12 Controls come out of risk treatment, and Annex A is only the check that nothing was forgotten; the Statement of Applicability records both decisions. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · ISO/IEC · 2022 ✓ Quiz · 3 questions › 13 Objectives must be measured and communicated, changes must be planned, and competence must be evidenced: clauses 6.2, 6.3 and 7 turn intent into evidence. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · ISO/IEC · 2022 ✓ Quiz · 3 questions › 14 Clauses 6.1.2 and 6.1.3 ask for the method, while 8.2 and 8.3 ask for it to be run: the same words, a different verb and different evidence. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · ISO/IEC · 2022 ✓ Quiz · 3 questions › 15 Clause 9 asks for three different things: measure, audit yourself with an independent eye, and put the results on management's table. ISO 19011:2026 — Guidelines for auditing management systems · ISO · 2026 ✓ Quiz · 3 questions › 16 A correction fixes the incident, a corrective action fixes the reason it was possible; the standard asks for both, and the auditor tells them apart. Out of the Crisis · W. Edwards Deming · 1986 ✓ Quiz · 3 questions › 17 The 2022 Annex A holds 93 controls in four themes and is a cross-check list, not a project plan you must tick off in full. ISO/IEC 27001:2022 — Information security, cybersecurity and privacy protection — Information security management systems — Requirements · ISO/IEC · 2022 ✓ Quiz · 3 questions › 18 A useful gap analysis compares the requirement with the evidence that exists, not with intent: what the standard asks, what you have, who closes the difference and by when. The Art of War · Sun Tzu, traducere Lionel Giles · 1910 ✓ Quiz · 3 questions › 19 Certification is not an event but a three-year cycle: two stages at the start, surveillance every year, recertification at the end. Remarks on Signing the Intermediate-Range Nuclear Forces Treaty · Ronald Reagan · 1987 ✓ Quiz · 3 questions › 20 An audit finding is not an opinion: it is a departure from a requirement, resting on something verifiable, and its severity decides whether the certificate can still be issued. ISO 19011:2018 — Guidelines for auditing management systems · ISO · 2018 ✓ Quiz · 3 questions › 21 Since 1 November 2025 there are no certificates on the 2013 edition: every audit runs against 2022, with an Annex A of 93 controls and climate in the context. IAF MD 26:2023 — Transition Requirements for ISO/IEC 27001:2022 · International Accreditation Forum · 2023 ✓ Quiz · 3 questions › 22 NIS2 moves security out of the technical basement and into the boardroom: the measures become legal duties, and management is personally answerable for them. Directiva (UE) 2022/2555 privind măsuri pentru un nivel comun ridicat de securitate cibernetică în Uniune · Parlamentul European și Consiliul Uniunii Europene · 2022 ✓ Quiz · 3 questions › 23 DORA asks not for a security management system but for demonstrated resilience: that it holds, that you know who holds your keys, that you tested it. Regulamentul (UE) 2022/2554 privind reziliența operațională digitală a sectorului financiar · Parlamentul European și Consiliul Uniunii Europene · 2022 ✓ Quiz · 3 questions › 24 From 11 September 2026, any product with digital elements sold in the Union carries reporting duties for actively exploited vulnerabilities, with a 24-hour clock running. Regulamentul (UE) 2024/2847 privind cerințe orizontale de securitate cibernetică pentru produsele cu elemente digitale · Parlamentul European și Consiliul Uniunii Europene · 2024 ✓ Quiz · 3 questions › 25 An artificial intelligence management system is not built beside the security one but inside it: the same clauses, a different risk register. Regulamentul (UE) 2024/1689 de stabilire a unor norme armonizate privind inteligența artificială · Parlamentul European și Consiliul Uniunii Europene · 2024 ✓ Quiz · 3 questions › 26 In 2026 compliance moves from the annual folder to continuous evidence, and certification becomes the platform several frameworks rest on at once. Recomandarea (UE) 2024/1101 privind o foaie de parcurs coordonată de punere în aplicare a tranziției la criptografia post-cuantică · Comisia Europeană · 2024 ✓ Quiz · 3 questions ›