ISO 27000 Foundation Certification ISMS Implementation and Operation 4 — Questions and Answers
Question 1: What distinguishes an 'information security objective' from a general security policy statement?
- Objectives are vague aspirations while policies are measurable
- Objectives are specific, measurable targets aligned with the security policy (Correct answer)
- Objectives only apply to technical controls, not process controls
- Objectives are set by auditors, not by the organization
Correct answer: Objectives are specific, measurable targets aligned with the security policy
Information security objectives must be measurable (where practical), consistent with the policy, and monitored for progress.
Question 2: During ISMS implementation, who holds ultimate accountability for accepting residual risk?
- The external auditor
- The IT security analyst
- Top management or designated risk owners (Correct answer)
- The third-party consultant
Correct answer: Top management or designated risk owners
Risk owners, approved by top management, are accountable for accepting residual risk after treatment options have been applied.
Question 3: What does the ISMS 'Plan-Do-Check-Act' cycle emphasize during the 'Do' phase?
- Setting security objectives and identifying risks
- Implementing and operating the ISMS controls as planned (Correct answer)
- Monitoring, measuring, and auditing ISMS performance
- Taking corrective and improvement actions
Correct answer: Implementing and operating the ISMS controls as planned
The 'Do' phase involves executing the plans made in 'Plan,' putting controls, processes, and procedures into practice.
Question 4: Which of the following is a valid risk treatment option under ISO 27001?
- Risk elimination by shutting down all digital systems
- Risk modification through applying security controls (Correct answer)
- Risk creation by intentionally introducing new vulnerabilities
- Risk substitution by replacing management
Correct answer: Risk modification through applying security controls
ISO 27001 risk treatment options include modification (applying controls), avoidance, sharing/transfer, and retention — not elimination or creation.
Question 5: A new employee joins a department that processes confidential customer data. What ISMS onboarding step is most critical?
- Issuing a company laptop immediately without any access review
- Providing information security awareness training before granting data access (Correct answer)
- Waiting until the annual training cycle to include the new employee
- Relying on peer employees to informally explain security rules
Correct answer: Providing information security awareness training before granting data access
New employees must receive security awareness training aligned to their role before handling sensitive information, per ISO 27001 Clause 7.3.
Question 6: What is the purpose of maintaining an 'asset inventory' during ISMS operation?
- To calculate the replacement cost of hardware for insurance purposes only
- To identify assets within scope so appropriate controls can be applied (Correct answer)
- To satisfy financial accounting requirements under GAAP
- To track employee performance related to asset usage
Correct answer: To identify assets within scope so appropriate controls can be applied
An asset inventory identifies what information assets exist within scope, enabling the organization to assign ownership and apply appropriate protections.
Question 7: How should an organization handle a situation where two ISMS controls conflict with each other operationally?
- Disable both controls until the conflict is resolved at the next annual review
- Document the conflict, assess the risk, and implement a compensating control or resolution (Correct answer)
- Escalate to the external certification body for a ruling
- Remove the less expensive control to reduce costs
Correct answer: Document the conflict, assess the risk, and implement a compensating control or resolution
Control conflicts must be documented, risk-assessed, and resolved through compensating controls or process adjustments to maintain security posture.
What distinguishes an 'information security objective' from a general security policy statement?