โ† All ISO 27000 Foundation Certification Flashcard Decks

ISMS Fundamentals and Vocabulary Flashcards

6 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 ISMS Fundamentals and Vocabulary flashcards as text
  1. According to ISO/IEC 27000, which of the following BEST defines 'confidentiality' as a core principle of information security?

    Answer: The property that information is not made available or disclosed to unauthorized individuals, entities, or processes.

    ISO/IEC 27000:2018 explicitly defines confidentiality as 'the property that information is not made available or disclosed to unauthorized individuals, entities, or processes'. This is a fundamental component of the CIA triad, which forms the basis of information security.

  2. A financial company identifies that a disgruntled former employee still possesses network access credentials. In the context of an ISMS based on ISO 27000, what does this situation primarily represent?

    Answer: A threat

    ISO/IEC 27000 defines a threat as a 'potential cause of an unwanted incident, which may result in harm to a system or organization'. The disgruntled former employee with credentials is the potential cause of an incident; they are the threat agent.

  3. Which standard in the ISO 27000 family provides the overview, fundamental principles, and vocabulary for Information Security Management Systems (ISMS)?

    Answer: ISO/IEC 27000

    ISO/IEC 27000 is the foundational standard in the series. It provides a comprehensive overview of ISMS, introduces key concepts, and, most importantly, establishes the formal terms and definitions used throughout the entire ISO/IEC 27000 family of standards.

  4. An organization's server room lacks a fire suppression system. According to the vocabulary of ISO 27000, this deficiency is best described as a(n):

    Answer: Vulnerability

    A vulnerability is defined as a 'weakness of an asset or control that can be exploited by one or more threats'. The absence of a fire suppression system is a weakness in the physical protection of the server room asset, which could be exploited by a threat (i.e., a fire).

  5. What are the three core components of the CIA triad, as defined in ISO/IEC 27000, that an ISMS is designed to preserve?

    Answer: Confidentiality, Integrity, and Availability

    ISO/IEC 27000 defines the three fundamental principles of information security as the CIA triad: Confidentiality, Integrity, and Availability. These three principles are the cornerstone of an ISMS and represent the primary objectives for protecting information assets.

  6. Which of the following is the PRIMARY purpose of an Information Security Management System (ISMS) as described in the ISO 27000 series?

    Answer: To establish, implement, maintain, and continually improve information security within an organization.

    The ISO 27000 family of standards describes an ISMS as a systematic approach for establishing, implementing, operating, monitoring, reviewing, maintaining, and improving an organization's information security to achieve business objectives. It is a continuous, process-based approach, not just a one-time implementation of technology.