โ† All ISO 27000 Foundation Certification Flashcard Decks

ISMS Implementation and Operation Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 ISMS Implementation and Operation flashcards as text
  1. Which statement correctly describes the relationship between risk assessment and risk treatment in an operational ISMS?

    Answer: Risk assessment identifies and evaluates risks; risk treatment decides how to address them

    Risk assessment produces a risk profile, which then informs the risk treatment process that selects and implements appropriate controls.

  2. When an organization changes its IT infrastructure significantly, what ISMS action is immediately required?

    Answer: Conduct a risk reassessment to account for changes in the threat landscape

    Significant changes trigger a reassessment of risks because new assets, technologies, or configurations may introduce previously unidentified threats.

  3. What is the role of 'internal communication' in an operational ISMS?

    Answer: It ensures relevant information security matters are communicated internally on time

    ISO 27001 Clause 7.4 requires the organization to determine what, when, how, and to whom information security information must be communicated internally.

  4. A company decides to accept a risk rather than apply a control. What must be documented?

    Answer: A formal risk acceptance decision approved by the risk owner

    Risk acceptance must be formally documented and approved by the designated risk owner as part of the risk treatment record.

  5. Which metric would best demonstrate the operational effectiveness of an ISMS access control process?

    Answer: Percentage of access rights reviewed and revoked within the required timeframe

    Measuring timely access reviews and revocations directly indicates whether the access control process is functioning as intended.

  6. What does 'continual improvement' of the ISMS primarily rely on?

    Answer: Findings from audits, nonconformities, monitoring results, and management review outputs

    Continual improvement draws on audit findings, incident data, nonconformities, performance measurements, and management review decisions.

  7. Under ISO 27001, what happens if the ISMS scope changes after initial certification?

    Answer: The organization must review and update the scope statement and assess impact on the ISMS

    Scope changes require the organization to update the scope document, reassess risks affected by the change, and adjust controls accordingly.