Governance and Leadership Flashcards
6 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Governance and Leadership flashcards as text
According to ISO 27001, who holds ultimate accountability for the ISMS?
Answer: Top management
ISO 27001 requires top management to take ultimate accountability for establishing, implementing, and maintaining the ISMS.
Which document formally expresses an organization's commitment to information security under ISO 27001?
Answer: Information security policy
The information security policy is the top-level document that formally communicates management's commitment and direction for information security.
What must the information security policy be in accordance with, according to ISO 27001?
Answer: The organization's strategic direction
ISO 27001 requires that the information security policy be appropriate to and aligned with the organization's overall strategic direction.
Who is responsible for defining the scope of the ISMS in ISO 27001?
Answer: Top management
Top management is responsible for determining and approving the boundaries and applicability of the ISMS, i.e., its scope.
Which of the following is a key leadership activity required by ISO 27001?
Answer: Ensuring integration of ISMS requirements into business processes
ISO 27001 requires top management to ensure that ISMS requirements are integrated into the organization's business processes.
How must an organization's information security objectives relate to its overall business objectives?
Answer: They must be aligned and consistent
ISO 27001 requires information security objectives to be consistent with and support the overall organizational objectives.