ISO 27000 Foundation Certification Information Security 4 — Questions and Answers
Question 1: Which ISO/IEC 27000-series standard provides guidance on information security controls (the code of practice)?
- ISO/IEC 27001
- ISO/IEC 27002 (Correct answer)
- ISO/IEC 27003
- ISO/IEC 27004
Correct answer: ISO/IEC 27002
ISO/IEC 27002 provides guidance and best practice recommendations for implementing information security controls.
Question 2: An employee accidentally emails a confidential client list to the wrong recipient. Which CIA property has been compromised?
- Integrity
- Availability
- Confidentiality (Correct answer)
- Non-repudiation
Correct answer: Confidentiality
Confidentiality is breached when sensitive information is disclosed to unauthorized parties, even accidentally.
Question 3: In the context of ISO 27001, what is meant by 'continual improvement' of the ISMS?
- Adding new security tools every year
- Ongoing activities to enhance ISMS performance over time (Correct answer)
- Achieving ISO certification every three years
- Replacing legacy systems on a fixed schedule
Correct answer: Ongoing activities to enhance ISMS performance over time
Continual improvement means systematically enhancing ISMS effectiveness based on audit results, incidents, and performance metrics.
Question 4: What is the purpose of an internal audit in an ISO 27001-certified organization?
- To prepare financial statements for shareholders
- To confirm the ISMS conforms to requirements and is effectively implemented (Correct answer)
- To report security incidents to regulators
- To evaluate individual employee performance
Correct answer: To confirm the ISMS conforms to requirements and is effectively implemented
Internal audits verify that the ISMS meets the organization's own requirements and ISO 27001 requirements and is effectively maintained.
Question 5: Which term describes a potential cause of an unwanted incident that may harm an organization's assets?
- Vulnerability
- Risk
- Threat (Correct answer)
- Control
Correct answer: Threat
ISO 27000 defines a threat as a potential cause of an unwanted incident which may result in harm to a system or organization.
Question 6: During a management review of the ISMS, which input is considered essential under ISO 27001?
- Vendor contract renewals
- Results of information security risk assessments and treatment (Correct answer)
- Employee satisfaction surveys
- Marketing performance metrics
Correct answer: Results of information security risk assessments and treatment
ISO 27001 clause 9.3 requires management reviews to consider results of risk assessments and the status of risk treatment actions.
Question 7: What is 'information security governance' primarily concerned with?
- The technical implementation of firewalls and encryption
- The day-to-day IT operations of an organization
- Directing and controlling information security at the organizational level (Correct answer)
- Writing detailed security procedures for system administrators
Correct answer: Directing and controlling information security at the organizational level
Information security governance involves leadership direction, oversight, and accountability for security at the strategic organizational level.
Which ISO/IEC 27000-series standard provides guidance on information security controls (the code of practice)?