ISO 27000 Foundation Certification Performance Evaluation and Improvement 4 — Questions and Answers
Question 1: A company's ISMS management review reveals that its risk appetite has changed due to a merger. Which management review output addresses this?
- Decisions on resource needs
- Decisions on continual improvement opportunities
- Decisions related to any need for changes to the ISMS (Correct answer)
- Actions to address nonconformities
Correct answer: Decisions related to any need for changes to the ISMS
ISO 27001 Clause 9.3 includes 'any need for changes to the ISMS' as a required output when strategic context changes like a merger occur.
Question 2: What does ISO 27004 primarily provide guidance on?
- Risk assessment methodology for ISMSs
- Monitoring, measurement, analysis, and evaluation of information security (Correct answer)
- Incident management procedures
- Supplier relationship security controls
Correct answer: Monitoring, measurement, analysis, and evaluation of information security
ISO 27004 provides guidelines on how to assess the performance of an ISMS and the controls specified in ISO 27001 through monitoring and measurement.
Question 3: Which of the following is NOT a required input to management review under ISO 27001 Clause 9.3?
- Feedback on information security performance including trends in nonconformities
- Results of risk assessment and status of the risk treatment plan
- Competitor analysis and market positioning reports (Correct answer)
- Opportunities for continual improvement
Correct answer: Competitor analysis and market positioning reports
ISO 27001 does not require competitor analysis as an input to management review — it focuses on ISMS performance, risk, and stakeholder feedback.
Question 4: An audit finding shows a control is documented but not actually practiced. This represents which type of nonconformity?
- A risk treatment gap
- A process conformance failure (Correct answer)
- A documentation nonconformity
- A legal compliance violation
Correct answer: A process conformance failure
When a documented control exists but is not implemented in practice, this is a process conformance failure — the ISMS is not effectively implemented.
Question 5: How should an organization handle metrics that consistently show 100% target achievement?
- Increase the target or evaluate whether the metric still provides meaningful insight (Correct answer)
- Archive the metric and stop collecting it
- Report it as a success and take no further action
- Replace it with a financial cost-per-incident metric
Correct answer: Increase the target or evaluate whether the metric still provides meaningful insight
Metrics that always show 100% may be set too loosely and should be challenged to ensure they still provide meaningful performance insight.
Question 6: What is the purpose of the 'analyze and evaluate' step after monitoring and measurement in ISO 27001 Clause 9.1?
- To assign blame for security failures
- To determine whether the ISMS is performing as required and to identify opportunities for improvement (Correct answer)
- To generate reports for external regulators only
- To decide which employees need disciplinary action
Correct answer: To determine whether the ISMS is performing as required and to identify opportunities for improvement
Analysis and evaluation of monitoring data is used to assess ISMS performance and identify areas needing improvement.
Question 7: Which of the following best describes a 'corrective action' under ISO 27001 Clause 10.1?
- A preventive measure taken before any nonconformity occurs
- An action taken to eliminate the cause of a detected nonconformity (Correct answer)
- A compensating control that mitigates residual risk
- A management directive to increase the security budget
Correct answer: An action taken to eliminate the cause of a detected nonconformity
A corrective action addresses the root cause of an identified nonconformity to prevent its recurrence, not just its immediate symptom.
A company's ISMS management review reveals that its risk appetite has changed due to a merger.
Which management review output addresses this?