ISO 27000 Foundation Certification Governance and Leadership 2 — Questions and Answers
Question 1: In ISO 27001 terminology, who are 'interested parties'?
- Only the organization's shareholders
- Persons or organizations that can affect or be affected by the ISMS (Correct answer)
- Only internal employees
- Regulatory bodies only
Correct answer: Persons or organizations that can affect or be affected by the ISMS
Interested parties (stakeholders) are any persons or organizations whose needs and expectations must be considered when establishing the ISMS.
Question 2: What is the purpose of assigning information security roles and responsibilities in ISO 27001?
- To reduce the number of employees needed
- To ensure accountability and clarity in protecting information assets (Correct answer)
- To comply with software licensing rules
- To create a security budget
Correct answer: To ensure accountability and clarity in protecting information assets
Clearly defined roles and responsibilities ensure that every aspect of information security is owned, monitored, and actioned by specific individuals.
Question 3: Which ISO standard provides specific guidance on information security governance at the enterprise level?
- ISO 27003
- ISO 27014 (Correct answer)
- ISO 27005
- ISO 27017
Correct answer: ISO 27014
ISO 27014 provides guidance on the governance of information security, addressing the roles of the governing body and executive management.
Question 4: What does 'organizational context' mean in the ISO 27001 framework?
- The physical layout of server rooms
- Understanding internal and external factors that influence the ISMS (Correct answer)
- The software tools used for security
- The number of employees in IT
Correct answer: Understanding internal and external factors that influence the ISMS
Organizational context requires identifying internal and external issues, as well as interested parties, that are relevant to the organization's information security objectives.
Question 5: How should information security responsibilities be communicated to employees according to ISO 27001?
- Only verbally during onboarding
- Through documented policies, procedures, and awareness programs (Correct answer)
- Via annual performance reviews only
- Through IT system access logs
Correct answer: Through documented policies, procedures, and awareness programs
ISO 27001 requires that roles and responsibilities be documented and communicated through formal policies, procedures, and ongoing awareness activities.
Question 6: What is the significance of the 'Statement of Applicability' (SoA) in governance terms?
- It replaces the risk assessment entirely
- It records which Annex A controls are applicable and justifies inclusions and exclusions (Correct answer)
- It lists all employees with security clearance
- It defines the ISMS project timeline
Correct answer: It records which Annex A controls are applicable and justifies inclusions and exclusions
The SoA is a critical governance document that maps Annex A controls to the organization's risk treatment decisions, explaining why each control is included or excluded.
In ISO 27001 terminology, who are 'interested parties'?