ISO 27000 Foundation Certification Information Security 2 — Questions and Answers
Question 1: According to ISO 27000, what is the primary purpose of an Information Security Management System (ISMS)?
- To eliminate all security risks
- To provide a systematic approach to managing sensitive information (Correct answer)
- To comply with government regulations only
- To restrict employee access to systems
Correct answer: To provide a systematic approach to managing sensitive information
An ISMS provides a systematic, risk-based approach to managing sensitive company information so it remains secure.
Question 2: Which ISO/IEC standard specifically provides requirements for establishing and maintaining an ISMS?
- ISO/IEC 27000
- ISO/IEC 27001 (Correct answer)
- ISO/IEC 27002
- ISO/IEC 27005
Correct answer: ISO/IEC 27001
ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an ISMS.
Question 3: In information security, what does 'non-repudiation' ensure?
- Data cannot be read by unauthorized parties
- A party cannot deny having performed an action (Correct answer)
- Systems remain available during attacks
- Backups are created automatically
Correct answer: A party cannot deny having performed an action
Non-repudiation ensures that a party cannot deny the authenticity of their signature or the sending of a message.
Question 4: What is the term for any weakness in a system that could be exploited by a threat?
- Risk
- Threat
- Vulnerability (Correct answer)
- Impact
Correct answer: Vulnerability
A vulnerability is a weakness in a system, process, or control that could be exploited by a threat source.
Question 5: Which of the following best describes 'residual risk'?
- Risk before any controls are applied
- Risk that remains after controls have been implemented (Correct answer)
- Risk transferred to a third party
- Risk that is deemed acceptable without treatment
Correct answer: Risk that remains after controls have been implemented
Residual risk is the remaining risk after risk treatment measures have been applied.
Question 6: Under ISO 27001, who holds ultimate accountability for the ISMS?
- The IT Security Manager
- The Risk Committee
- Top management (Correct answer)
- The ISO certification auditor
Correct answer: Top management
ISO 27001 clause 5 (Leadership) places accountability for the ISMS on top management of the organization.
Question 7: What does the 'Plan' phase of the PDCA cycle in an ISMS context involve?
- Implementing selected security controls
- Monitoring and reviewing ISMS performance
- Establishing security objectives and risk treatment plans (Correct answer)
- Taking corrective actions based on audit findings
Correct answer: Establishing security objectives and risk treatment plans
The Plan phase involves establishing ISMS objectives, risk assessment, and selecting appropriate controls and treatment plans.
According to ISO 27000, what is the primary purpose of an Information Security Management System (ISMS)?