Performance Evaluation and Improvement Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Performance Evaluation and Improvement flashcards as text
A company's ISMS management review reveals that its risk appetite has changed due to a merger. Which management review output addresses this?
Answer: Decisions related to any need for changes to the ISMS
ISO 27001 Clause 9.3 includes 'any need for changes to the ISMS' as a required output when strategic context changes like a merger occur.
What does ISO 27004 primarily provide guidance on?
Answer: Monitoring, measurement, analysis, and evaluation of information security
ISO 27004 provides guidelines on how to assess the performance of an ISMS and the controls specified in ISO 27001 through monitoring and measurement.
Which of the following is NOT a required input to management review under ISO 27001 Clause 9.3?
Answer: Competitor analysis and market positioning reports
ISO 27001 does not require competitor analysis as an input to management review — it focuses on ISMS performance, risk, and stakeholder feedback.
An audit finding shows a control is documented but not actually practiced. This represents which type of nonconformity?
Answer: A process conformance failure
When a documented control exists but is not implemented in practice, this is a process conformance failure — the ISMS is not effectively implemented.
How should an organization handle metrics that consistently show 100% target achievement?
Answer: Increase the target or evaluate whether the metric still provides meaningful insight
Metrics that always show 100% may be set too loosely and should be challenged to ensure they still provide meaningful performance insight.
What is the purpose of the 'analyze and evaluate' step after monitoring and measurement in ISO 27001 Clause 9.1?
Answer: To determine whether the ISMS is performing as required and to identify opportunities for improvement
Analysis and evaluation of monitoring data is used to assess ISMS performance and identify areas needing improvement.
Which of the following best describes a 'corrective action' under ISO 27001 Clause 10.1?
Answer: An action taken to eliminate the cause of a detected nonconformity
A corrective action addresses the root cause of an identified nonconformity to prevent its recurrence, not just its immediate symptom.