The PDCA Cycle Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 The PDCA Cycle flashcards as text
In the PDCA model, what is the primary risk of skipping the 'Check' phase?
Answer: Ineffective controls may go undetected, leaving the organization exposed
Without Check phase activities, failed or ineffective controls are not identified, undermining the entire ISMS.
An organization is implementing security awareness training as part of its risk treatment plan. This is an example of which PDCA phase?
Answer: Do
Implementing controls and programs defined in the risk treatment plan is a Do phase activity.
Which of the following scenarios best represents a 'Plan' phase failure in an ISO 27001 ISMS?
Answer: Risk assessments do not consider all relevant assets
Incomplete risk assessment during the Plan phase leads to gaps in the risk treatment plan and unmitigated risks.
What role does the Statement of Applicability (SoA) play in the PDCA cycle?
Answer: It is a Plan phase output that links Annex A controls to the risk treatment decisions
The SoA is created during the Plan phase to document which Annex A controls are applicable, included, or excluded and why.
How does the PDCA cycle relate to the concept of 'risk-based thinking' in ISO/IEC 27001?
Answer: Risk assessment and treatment in the Plan phase drive all subsequent PDCA phases
Risk assessment in the Plan phase determines what controls to implement (Do), monitor (Check), and improve (Act).
During a PDCA cycle review, management finds that several key performance indicators (KPIs) are below target. Which phase comes next?
Answer: Act phase to take corrective actions and improve
When Check reveals underperformance, the Act phase initiates corrective actions to address root causes.
Which ISO/IEC 27000 series standard specifically defines the PDCA model's application to information security management?
Answer: ISO/IEC 27001
ISO/IEC 27001 is the ISMS requirements standard that formally applies the PDCA model to information security management.