ISO 27000 Foundation Certification Performance Evaluation and Improvement 5 — Questions and Answers
Question 1: What distinguishes a 'correction' from a 'corrective action' in ISO management system terminology?
- Corrections are more expensive; corrective actions are cost-effective
- A correction fixes the immediate problem; a corrective action eliminates the root cause (Correct answer)
- Corrections are documented; corrective actions are informal
- There is no difference — both terms mean the same thing
Correct answer: A correction fixes the immediate problem; a corrective action eliminates the root cause
A correction addresses the immediate nonconformity (e.g., fixing a misconfigured firewall), while a corrective action addresses the root cause to prevent recurrence.
Question 2: Under ISO 27001, which of the following best represents 'continual improvement'?
- A one-time project to upgrade all security technologies
- Recurring activities to enhance the ISMS's suitability, adequacy, and effectiveness over time (Correct answer)
- Annual replacement of the ISMS policy documents
- Hiring additional security staff each year
Correct answer: Recurring activities to enhance the ISMS's suitability, adequacy, and effectiveness over time
Continual improvement is an ongoing effort to enhance ISMS performance and is a core requirement of ISO 27001 Clause 10.2.
Question 3: A penetration test is conducted on the organization's network. In ISMS terms, this is best classified as which activity?
- Risk treatment
- Performance evaluation through technical testing (Correct answer)
- An internal audit
- A management review input only
Correct answer: Performance evaluation through technical testing
Penetration testing is a form of technical evaluation that measures the real-world effectiveness of security controls, fitting within performance evaluation.
Question 4: When reviewing ISMS metrics, management notices a gradual upward trend in phishing email click rates over six months. Which action is most appropriate?
- Wait 12 months before acting to confirm the trend
- Investigate root causes and implement corrective actions such as enhanced training (Correct answer)
- Report the trend to the regulator immediately
- Remove the phishing click-rate metric from the dashboard
Correct answer: Investigate root causes and implement corrective actions such as enhanced training
A negative trend in a key metric signals a degrading control that requires root cause analysis and corrective action rather than delay or avoidance.
Question 5: Which of the following is a valid measure of ISMS effectiveness related to incident response?
- Number of new employees hired in the IT department
- Mean time to detect and respond to security incidents (Correct answer)
- Total lines of code in security applications
- Number of security policies published on the intranet
Correct answer: Mean time to detect and respond to security incidents
Mean time to detect (MTTD) and mean time to respond (MTTR) are direct measures of how effectively the incident response process is performing.
Question 6: What documented information must be retained as evidence of the management review process under ISO 27001?
- Only the meeting agenda
- Results of the management review (Correct answer)
- Individual employee performance reviews
- Budget approval documents for security projects
Correct answer: Results of the management review
ISO 27001 Clause 9.3 requires that the organization retain documented information as evidence of the results of management reviews.
Question 7: An organization applies a new email filtering control after a phishing incident. Six months later, phishing-related incidents drop by 70%. This outcome most directly demonstrates what?
- Successful risk transfer
- Control effectiveness confirmed through measurement (Correct answer)
- Completion of the planning phase
- Compliance with legal requirements
Correct answer: Control effectiveness confirmed through measurement
Measuring the incident reduction rate after control implementation is a direct demonstration of that control's effectiveness, confirming it is working as intended.
What distinguishes a 'correction' from a 'corrective action' in ISO management system terminology?