ISO 27000 Foundation Certification The PDCA Cycle 3 — Questions and Answers
Question 1: Which of the following best describes the relationship between PDCA and ISO/IEC 27001's Annex A controls?
- Annex A controls only apply during the Check phase
- Annex A controls are selected and implemented as part of Do, following risk treatment decisions made in Plan (Correct answer)
- Annex A controls replace the need for a PDCA cycle
- Annex A controls are reviewed exclusively in the Act phase
Correct answer: Annex A controls are selected and implemented as part of Do, following risk treatment decisions made in Plan
Risk treatment in Plan identifies which Annex A controls are needed, and these are then implemented during the Do phase.
Question 2: What document produced in the Plan phase specifies which risks will be treated and how?
- Statement of Applicability
- Risk Treatment Plan (Correct answer)
- Business Continuity Plan
- Information Security Policy
Correct answer: Risk Treatment Plan
The Risk Treatment Plan documents selected risk treatment options and the controls needed for each identified risk.
Question 3: In which PDCA phase would management review of the ISMS typically occur?
- Plan
- Do
- Check (Correct answer)
- Act
Correct answer: Check
Management review is a monitoring activity in the Check phase that evaluates the ISMS performance and suitability.
Question 4: A security team patches a critical vulnerability immediately after it is discovered. Which PDCA phase does this reactive patching represent?
- Plan
- Do
- Check
- Act (Correct answer)
Correct answer: Act
Reacting to a discovered problem with a corrective action falls within the Act phase of the PDCA cycle.
Question 5: Which of the following is an output of the 'Check' phase in an ISO 27001 ISMS?
- A list of applicable controls
- An updated risk register
- Audit reports and nonconformity records (Correct answer)
- A completed employee training program
Correct answer: Audit reports and nonconformity records
Audit reports and nonconformity records are typical outputs of the Check phase's monitoring and measurement activities.
Question 6: Why is it important that the PDCA cycle in an ISMS is iterative rather than a one-time process?
- Because ISO 27001 requires certification to be renewed annually
- Because the threat landscape, business context, and technology change continuously (Correct answer)
- Because PDCA is only applicable during the initial ISMS setup
- Because regulatory requirements never change
Correct answer: Because the threat landscape, business context, and technology change continuously
Threats, vulnerabilities, and business requirements evolve constantly, making ongoing iteration of the PDCA cycle essential.
Question 7: Which PDCA phase includes defining the ISMS scope?
- Do
- Check
- Act
- Plan (Correct answer)
Correct answer: Plan
Defining the ISMS scope is a foundational planning activity that determines what the ISMS will cover.
Which of the following best describes the relationship between PDCA and ISO/IEC 27001's Annex A controls?