ISO 27000 Foundation Certification ISMS Implementation and Operation 5 — Questions and Answers
Question 1: Which statement correctly describes the relationship between risk assessment and risk treatment in an operational ISMS?
- Risk treatment is performed first, then assessment validates the results
- Risk assessment identifies and evaluates risks; risk treatment decides how to address them (Correct answer)
- Both activities are identical and can be performed by the same document
- Risk assessment is only required for the initial ISMS certification audit
Correct answer: Risk assessment identifies and evaluates risks; risk treatment decides how to address them
Risk assessment produces a risk profile, which then informs the risk treatment process that selects and implements appropriate controls.
Question 2: When an organization changes its IT infrastructure significantly, what ISMS action is immediately required?
- Suspend the ISMS until a full re-certification audit is completed
- Conduct a risk reassessment to account for changes in the threat landscape (Correct answer)
- Notify the ISO certification body within 24 hours as a mandatory requirement
- Revert the infrastructure change to maintain ISMS continuity
Correct answer: Conduct a risk reassessment to account for changes in the threat landscape
Significant changes trigger a reassessment of risks because new assets, technologies, or configurations may introduce previously unidentified threats.
Question 3: What is the role of 'internal communication' in an operational ISMS?
- It is optional and only required if an incident occurs
- It ensures relevant information security matters are communicated internally on time (Correct answer)
- It replaces the need for documented policies and procedures
- It is limited to communications between the CISO and board members
Correct answer: It ensures relevant information security matters are communicated internally on time
ISO 27001 Clause 7.4 requires the organization to determine what, when, how, and to whom information security information must be communicated internally.
Question 4: A company decides to accept a risk rather than apply a control. What must be documented?
- Nothing — risk acceptance requires no documentation
- A formal risk acceptance decision approved by the risk owner (Correct answer)
- A contract with an insurance company to cover the risk
- A board resolution signed by all executive directors
Correct answer: A formal risk acceptance decision approved by the risk owner
Risk acceptance must be formally documented and approved by the designated risk owner as part of the risk treatment record.
Question 5: Which metric would best demonstrate the operational effectiveness of an ISMS access control process?
- Number of servers in the data center
- Percentage of access rights reviewed and revoked within the required timeframe (Correct answer)
- Total number of employees in the organization
- Annual IT budget allocated to cybersecurity
Correct answer: Percentage of access rights reviewed and revoked within the required timeframe
Measuring timely access reviews and revocations directly indicates whether the access control process is functioning as intended.
Question 6: What does 'continual improvement' of the ISMS primarily rely on?
- Replacing all staff annually to bring fresh perspectives
- Findings from audits, nonconformities, monitoring results, and management review outputs (Correct answer)
- Increasing the ISMS budget each fiscal year
- Adopting every new security technology as it becomes available
Correct answer: Findings from audits, nonconformities, monitoring results, and management review outputs
Continual improvement draws on audit findings, incident data, nonconformities, performance measurements, and management review decisions.
Question 7: Under ISO 27001, what happens if the ISMS scope changes after initial certification?
- The certification is automatically revoked and must be re-applied for from scratch
- The organization must review and update the scope statement and assess impact on the ISMS (Correct answer)
- Scope changes are prohibited during the three-year certification cycle
- Only the external auditor may approve and document the scope change
Correct answer: The organization must review and update the scope statement and assess impact on the ISMS
Scope changes require the organization to update the scope document, reassess risks affected by the change, and adjust controls accordingly.
Which statement correctly describes the relationship between risk assessment and risk treatment in an operational ISMS?