ISO 27000 Foundation Certification MCQ Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 ISO 27000 Foundation Certification MCQ flashcards as text
What has to be done as part of the monitoring, measuring, analysis, and evaluation process?
Answer: Evaluate the effectiveness of the ISMS
Clause 9.1 of ISO 27001, 'Monitoring, measurement, analysis and evaluation,' explicitly requires the organization to evaluate the information security performance and the effectiveness of the ISMS. This is a crucial step to ensure that the implemented controls and processes are achieving their intended outcomes and adequately protecting information assets.
Which task must be completed while analyzing risks?
Answer: Determine the likelihood of the occurrence of the risks
Risk analysis, as a key part of the risk assessment process (Clause 6.1.2), involves identifying risks, determining their likelihood of occurrence, and evaluating their potential consequences. Determining the likelihood helps the organization understand the probability of a risk materializing, which is essential for prioritizing and selecting appropriate treatment options.
Find the terms that are absent from the following phrase. The company must decide which __ are relevant to its goal to comprehend what can prevent the ISMS from producing the desired results.
Answer: External and internal issues
Clause 4.1 of ISO 27001, 'Understanding the organization and its context,' requires the organization to determine external and internal issues that are relevant to its purpose and that can affect its ability to achieve the intended outcomes of its ISMS. These issues provide the foundational context for establishing and maintaining the ISMS.
Which benefit does running an information security management system NOT provide?
Answer: Eliminate all information security vulnerabilities in the organization
While an ISMS significantly reduces information security risks and vulnerabilities, it is impossible to eliminate *all* vulnerabilities. Information security is an ongoing process, and new threats and vulnerabilities constantly emerge. The goal of an ISMS is to manage and reduce risk to an acceptable level, not to achieve absolute elimination of all vulnerabilities.
What elements must be taken into account while deciding the ISMS's scope?
Answer: External and internal issues
Clause 4.3 of ISO 27001, 'Determining the scope of the information security management system,' explicitly states that the organization shall consider the external and internal issues referred to in 4.1 when defining its ISMS scope. This ensures the scope is relevant to the organization's context, objectives, and the interested parties' requirements.
Which activity DOES NOT fall under a certifying body's mandates and obligations?
Answer: Advise how to fill the gaps found during a readiness assessment
A certifying body's role is to conduct independent audits and assess an organization's conformity to the standard, maintaining impartiality. Providing specific advice on how to fill gaps or implement controls would be considered consulting, which creates a conflict of interest for a certifying body. They identify nonconformities but do not prescribe solutions.
What kind of action is necessary in light of the suggested residual risks?
Answer: Risk owners shall approve their acceptance
After risk treatment, any remaining risks are considered residual risks. ISO 27001 requires that these residual risks be formally approved and accepted by the risk owners. This ensures accountability and acknowledges that some level of risk will always remain, and management has consciously decided to bear it.