ISMS Implementation and Operation Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 ISMS Implementation and Operation flashcards as text
Which of the following best describes 'documented information' in the context of ISO 27001 ISMS operation?
Answer: Information that must be controlled and maintained, in any format or media
ISO 27001 uses 'documented information' broadly to mean any information that must be controlled, whether electronic, paper, or other media.
During ISMS operation, why is it important to retain documented information as evidence of results?
Answer: To provide objective evidence that ISMS processes were performed as planned
Retained documented information provides objective evidence during audits that ISMS activities were carried out and controls are functioning.
What is the correct sequence when an organization identifies a new threat during ISMS operation?
Answer: Assess the risk, update the risk register, and treat accordingly
New threats must be assessed for risk impact, logged in the risk register, and addressed through the risk treatment process.
How does ISO 27001 define 'competence' in the context of ISMS personnel?
Answer: The ability to apply knowledge and skills to achieve intended results
Competence means having the necessary education, training, or experience to perform information security roles effectively.
Which scenario best illustrates the ISMS 'awareness' requirement under ISO 27001 Clause 7.3?
Answer: All persons doing work under the organization's control understand the ISMS policy and their contribution to it
Clause 7.3 requires that all workers understand the policy, their role in achieving ISMS objectives, and the implications of non-conformity.
What is the main output of the risk treatment process within an operational ISMS?
Answer: A risk treatment plan and updated Statement of Applicability
Risk treatment produces a risk treatment plan detailing selected controls and updates the SoA to reflect implementation decisions.
An organization wants to outsource its data backup process. How should the ISMS address this?
Answer: Apply controls to externally provided processes and retain responsibility
ISO 27001 requires that externally provided processes still be controlled and managed within the ISMS; responsibility cannot be fully delegated.