โ† All ISO 27000 Foundation Certification Flashcard Decks

Performance Evaluation and Improvement Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Performance Evaluation and Improvement flashcards as text
  1. What distinguishes a 'correction' from a 'corrective action' in ISO management system terminology?

    Answer: A correction fixes the immediate problem; a corrective action eliminates the root cause

    A correction addresses the immediate nonconformity (e.g., fixing a misconfigured firewall), while a corrective action addresses the root cause to prevent recurrence.

  2. Under ISO 27001, which of the following best represents 'continual improvement'?

    Answer: Recurring activities to enhance the ISMS's suitability, adequacy, and effectiveness over time

    Continual improvement is an ongoing effort to enhance ISMS performance and is a core requirement of ISO 27001 Clause 10.2.

  3. A penetration test is conducted on the organization's network. In ISMS terms, this is best classified as which activity?

    Answer: Performance evaluation through technical testing

    Penetration testing is a form of technical evaluation that measures the real-world effectiveness of security controls, fitting within performance evaluation.

  4. When reviewing ISMS metrics, management notices a gradual upward trend in phishing email click rates over six months. Which action is most appropriate?

    Answer: Investigate root causes and implement corrective actions such as enhanced training

    A negative trend in a key metric signals a degrading control that requires root cause analysis and corrective action rather than delay or avoidance.

  5. Which of the following is a valid measure of ISMS effectiveness related to incident response?

    Answer: Mean time to detect and respond to security incidents

    Mean time to detect (MTTD) and mean time to respond (MTTR) are direct measures of how effectively the incident response process is performing.

  6. What documented information must be retained as evidence of the management review process under ISO 27001?

    Answer: Results of the management review

    ISO 27001 Clause 9.3 requires that the organization retain documented information as evidence of the results of management reviews.

  7. An organization applies a new email filtering control after a phishing incident. Six months later, phishing-related incidents drop by 70%. This outcome most directly demonstrates what?

    Answer: Control effectiveness confirmed through measurement

    Measuring the incident reduction rate after control implementation is a direct demonstration of that control's effectiveness, confirming it is working as intended.