ISMS Implementation and Operation Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 ISMS Implementation and Operation flashcards as text
During ISMS implementation, which document formally authorizes the start of the information security management system?
Answer: Management mandate or authorization
Top management must formally authorize and mandate the ISMS before implementation begins, demonstrating committed leadership.
What is the primary purpose of a Statement of Applicability (SoA) in an ISO 27001 ISMS?
Answer: To document which Annex A controls are applicable and their justification
The SoA documents selected controls from Annex A, justifies their inclusion or exclusion, and confirms implementation status.
Which ISO 27001 clause requires organizations to determine and provide resources needed for the ISMS?
Answer: Clause 7 โ Support
Clause 7 (Support) addresses resources, competence, awareness, communication, and documented information required for ISMS operation.
When implementing security controls, what does the term 'residual risk' mean?
Answer: Risk remaining after treatment measures have been applied
Residual risk is the level of risk that persists after controls are implemented and cannot be fully eliminated.
In the ISMS operational context, what does 'operational planning and control' primarily require?
Answer: Planning, implementing, and controlling processes needed to meet security requirements
ISO 27001 Clause 8 requires organizations to plan, implement, control, and review processes that address information security requirements.
Which activity ensures that ISMS processes continue to function correctly after initial implementation?
Answer: Ongoing monitoring, measurement, and review
Continuous monitoring and measurement are essential to verify that ISMS controls remain effective throughout operation.
What should an organization do when a planned information security objective cannot be achieved on schedule?
Answer: Escalate to top management and revise the plan with corrective actions
Unmet objectives must be escalated with a revised plan, ensuring accountability and corrective action in line with ISO 27001 requirements.