ISO 27000 Foundation Certification ISMS Implementation and Operation 3 — Questions and Answers
Question 1: Which of the following best describes 'documented information' in the context of ISO 27001 ISMS operation?
- Only paper-based policies stored in a locked cabinet
- Information that must be controlled and maintained, in any format or media (Correct answer)
- Emails exchanged between employees about security topics
- Verbal instructions given during security briefings
Correct answer: Information that must be controlled and maintained, in any format or media
ISO 27001 uses 'documented information' broadly to mean any information that must be controlled, whether electronic, paper, or other media.
Question 2: During ISMS operation, why is it important to retain documented information as evidence of results?
- To satisfy legal discovery requirements only
- To provide objective evidence that ISMS processes were performed as planned (Correct answer)
- To increase the organization's ISO certification fee tier
- To replace the need for management reviews
Correct answer: To provide objective evidence that ISMS processes were performed as planned
Retained documented information provides objective evidence during audits that ISMS activities were carried out and controls are functioning.
Question 3: What is the correct sequence when an organization identifies a new threat during ISMS operation?
- Immediately purchase new technology before assessing the threat
- Assess the risk, update the risk register, and treat accordingly (Correct answer)
- Ignore it until the next scheduled annual review
- Delete all data related to the threat to eliminate exposure
Correct answer: Assess the risk, update the risk register, and treat accordingly
New threats must be assessed for risk impact, logged in the risk register, and addressed through the risk treatment process.
Question 4: How does ISO 27001 define 'competence' in the context of ISMS personnel?
- Having a university degree in information security
- The ability to apply knowledge and skills to achieve intended results (Correct answer)
- Passing a one-time security awareness quiz
- Holding a managerial position within the IT department
Correct answer: The ability to apply knowledge and skills to achieve intended results
Competence means having the necessary education, training, or experience to perform information security roles effectively.
Question 5: Which scenario best illustrates the ISMS 'awareness' requirement under ISO 27001 Clause 7.3?
- Only the IT security team is briefed on the information security policy
- All persons doing work under the organization's control understand the ISMS policy and their contribution to it (Correct answer)
- Awareness training is conducted only when a breach occurs
- Vendors are responsible for their own staff awareness programs
Correct answer: All persons doing work under the organization's control understand the ISMS policy and their contribution to it
Clause 7.3 requires that all workers understand the policy, their role in achieving ISMS objectives, and the implications of non-conformity.
Question 6: What is the main output of the risk treatment process within an operational ISMS?
- A final list of all organizational assets
- A risk treatment plan and updated Statement of Applicability (Correct answer)
- A report submitted directly to regulators
- An updated organizational chart showing security roles
Correct answer: A risk treatment plan and updated Statement of Applicability
Risk treatment produces a risk treatment plan detailing selected controls and updates the SoA to reflect implementation decisions.
Question 7: An organization wants to outsource its data backup process. How should the ISMS address this?
- Exclude backups from the ISMS scope since they are outsourced
- Apply controls to externally provided processes and retain responsibility (Correct answer)
- Transfer all legal liability to the outsourcing vendor
- Remove the backup asset from the asset register
Correct answer: Apply controls to externally provided processes and retain responsibility
ISO 27001 requires that externally provided processes still be controlled and managed within the ISMS; responsibility cannot be fully delegated.
Which of the following best describes 'documented information' in the context of ISO 27001 ISMS operation?