Information Security Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Security flashcards as text
Which ISO/IEC 27000-series standard provides guidance on information security controls (the code of practice)?
Answer: ISO/IEC 27002
ISO/IEC 27002 provides guidance and best practice recommendations for implementing information security controls.
An employee accidentally emails a confidential client list to the wrong recipient. Which CIA property has been compromised?
Answer: Confidentiality
Confidentiality is breached when sensitive information is disclosed to unauthorized parties, even accidentally.
In the context of ISO 27001, what is meant by 'continual improvement' of the ISMS?
Answer: Ongoing activities to enhance ISMS performance over time
Continual improvement means systematically enhancing ISMS effectiveness based on audit results, incidents, and performance metrics.
What is the purpose of an internal audit in an ISO 27001-certified organization?
Answer: To confirm the ISMS conforms to requirements and is effectively implemented
Internal audits verify that the ISMS meets the organization's own requirements and ISO 27001 requirements and is effectively maintained.
Which term describes a potential cause of an unwanted incident that may harm an organization's assets?
Answer: Threat
ISO 27000 defines a threat as a potential cause of an unwanted incident which may result in harm to a system or organization.
During a management review of the ISMS, which input is considered essential under ISO 27001?
Answer: Results of information security risk assessments and treatment
ISO 27001 clause 9.3 requires management reviews to consider results of risk assessments and the status of risk treatment actions.
What is 'information security governance' primarily concerned with?
Answer: Directing and controlling information security at the organizational level
Information security governance involves leadership direction, oversight, and accountability for security at the strategic organizational level.