ISO 27000 Foundation Certification Information Security Incident Management 2 — Questions and Answers
Question 1: What is a vulnerability as defined in the ISO 27000 vocabulary?
- A confirmed attack that has compromised an information asset
- A weakness of an asset or control that can be exploited by one or more threats (Correct answer)
- The complete absence of security controls in an ISMS
- A type of malware specifically targeting ISO-certified organizations
Correct answer: A weakness of an asset or control that can be exploited by one or more threats
ISO 27000 defines a vulnerability as a weakness of an asset or control that can be exploited by one or more threats, representing a potential entry point for harm.
Question 2: What is the primary role of a Computer Security Incident Response Team (CSIRT)?
- To develop and maintain the organization's information security policies
- To conduct regular penetration tests on organizational systems
- To coordinate and manage the organization's response to information security incidents (Correct answer)
- To audit compliance with ISO 27001 certification requirements
Correct answer: To coordinate and manage the organization's response to information security incidents
A CSIRT is specifically established to coordinate and execute responses to information security incidents, ensuring a structured and effective handling process.
Question 3: How should digital evidence collected during an incident investigation be handled?
- Deleted securely once the incident is resolved to protect privacy
- Shared publicly with the security community to help prevent similar incidents
- Preserved in a manner that maintains its integrity and admissibility (Correct answer)
- Stored only in unencrypted digital format for ease of access by investigators
Correct answer: Preserved in a manner that maintains its integrity and admissibility
Evidence must be collected and preserved according to forensic best practices to maintain its integrity and ensure it remains admissible in legal proceedings if required.
Question 4: Which phase of incident management involves removing the threat and restoring systems to normal operation?
- Identification
- Containment
- Eradication and Recovery (Correct answer)
- Lessons Learned
Correct answer: Eradication and Recovery
The eradication and recovery phase involves removing malware, closing vulnerabilities, and restoring affected systems to their normal, trusted operational state.
Question 5: What is an escalation procedure in the context of incident management?
- A process for increasing security control stringency after a major incident
- A defined path for elevating an incident to higher management or specialists when needed (Correct answer)
- A method for encrypting and securing incident reports from unauthorized access
- A technique used to prevent low-level incidents from escalating into major ones
Correct answer: A defined path for elevating an incident to higher management or specialists when needed
Escalation procedures define when and how an incident should be elevated to higher authority or specialized teams when it exceeds the current responder's ability or authority to handle it.
Question 6: How does incident management relate to an organization's ISMS under ISO 27001?
- Incident management is a separate discipline and does not form part of the ISMS
- Incident management is a required component of the ISMS covering response and improvement (Correct answer)
- The ISMS only addresses prevention of incidents, not their management
- Incident management replaces the need for a formal ISMS in smaller organizations
Correct answer: Incident management is a required component of the ISMS covering response and improvement
ISO 27001 requires organizations to plan and implement incident management processes as a mandatory part of the ISMS, particularly through Annex A controls A.5.24 to A.5.28.
Question 7: What is the key benefit of classifying information security incidents by type and severity?
- Classification is required only to meet legal and regulatory reporting obligations
- It helps organizations allocate appropriate resources and set response priorities (Correct answer)
- Classification eliminates the need for formal incident reporting procedures
- It determines which commercial software tool should be used for incident tracking
Correct answer: It helps organizations allocate appropriate resources and set response priorities
Classifying incidents by type and severity enables organizations to prioritize response efforts and allocate the right level of resources, ensuring critical incidents receive immediate attention.
What is a vulnerability as defined in the ISO 27000 vocabulary?