โ† All ISO 27000 Foundation Certification Flashcard Decks

Scope of the ISMS Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Scope of the ISMS flashcards as text
  1. Which scenario demonstrates an inappropriate ISMS scope exclusion?

    Answer: Excluding an e-commerce platform that processes customer payment information

    Excluding an e-commerce platform that processes payment data is inappropriate because it handles sensitive information that falls under the organization's security obligations.

  2. What is the consequence if an organization's ISMS scope is too broad?

    Answer: Implementation becomes resource-intensive and may be ineffective across the entire scope

    A scope that is too broad can stretch resources thin, leading to superficial control implementation that may not effectively manage risks across all covered areas.

  3. How does the concept of 'interfaces and dependencies' affect ISMS scope decisions?

    Answer: It ensures that relationships with out-of-scope entities are considered so security gaps are not created at boundaries

    Identifying interfaces and dependencies helps the organization understand how out-of-scope activities can create security risks at the boundaries of the ISMS.

  4. A company's ISMS scope includes 'information in all formats.' What does this imply?

    Answer: Physical documents, verbal communications, and digital data are all within scope

    When scope includes 'information in all formats,' it encompasses digital, physical (paper), and other forms of information, ensuring comprehensive protection.

  5. Which stakeholder group has the MOST influence on determining the initial ISMS scope?

    Answer: Top management

    Top management is responsible for ensuring the ISMS aligns with organizational strategy and objectives, making them the most influential stakeholder in scope decisions.

  6. An organization operating in both healthcare and retail decides to certify only its healthcare division under ISO 27001. This is an example of:

    Answer: Defining ISMS scope by business unit or division

    Scoping the ISMS to a specific business division is a legitimate and common approach, provided the scope boundaries and any exclusions are properly documented.

  7. Which of the following best ensures that an ISMS scope remains valid over time?

    Answer: Regularly reviewing scope as part of management reviews and internal audits

    Regular management reviews and internal audits provide formal mechanisms to reassess and update the ISMS scope as the organization and its context change.