ISO 27000 Foundation Certification The PDCA Cycle 4 — Questions and Answers
Question 1: In the PDCA model, what is the primary risk of skipping the 'Check' phase?
- The ISMS will become too expensive to operate
- Ineffective controls may go undetected, leaving the organization exposed (Correct answer)
- New employees will not receive security training
- The risk treatment plan cannot be updated
Correct answer: Ineffective controls may go undetected, leaving the organization exposed
Without Check phase activities, failed or ineffective controls are not identified, undermining the entire ISMS.
Question 2: An organization is implementing security awareness training as part of its risk treatment plan. This is an example of which PDCA phase?
- Plan
- Do (Correct answer)
- Check
- Act
Correct answer: Do
Implementing controls and programs defined in the risk treatment plan is a Do phase activity.
Question 3: Which of the following scenarios best represents a 'Plan' phase failure in an ISO 27001 ISMS?
- Controls are implemented incorrectly by staff
- Risk assessments do not consider all relevant assets (Correct answer)
- Audit logs are not reviewed regularly
- Corrective actions are not tracked to closure
Correct answer: Risk assessments do not consider all relevant assets
Incomplete risk assessment during the Plan phase leads to gaps in the risk treatment plan and unmitigated risks.
Question 4: What role does the Statement of Applicability (SoA) play in the PDCA cycle?
- It is produced in the Do phase to document implemented controls
- It is a Plan phase output that links Annex A controls to the risk treatment decisions (Correct answer)
- It is a Check phase report on control effectiveness
- It is an Act phase document for continual improvement plans
Correct answer: It is a Plan phase output that links Annex A controls to the risk treatment decisions
The SoA is created during the Plan phase to document which Annex A controls are applicable, included, or excluded and why.
Question 5: How does the PDCA cycle relate to the concept of 'risk-based thinking' in ISO/IEC 27001?
- PDCA replaces the need for risk-based thinking
- Risk-based thinking is only applied during the Check phase
- Risk assessment and treatment in the Plan phase drive all subsequent PDCA phases (Correct answer)
- Risk-based thinking is an Act phase activity only
Correct answer: Risk assessment and treatment in the Plan phase drive all subsequent PDCA phases
Risk assessment in the Plan phase determines what controls to implement (Do), monitor (Check), and improve (Act).
Question 6: During a PDCA cycle review, management finds that several key performance indicators (KPIs) are below target. Which phase comes next?
- A new Plan phase to set lower KPI targets
- Do phase to re-implement the same controls
- Act phase to take corrective actions and improve (Correct answer)
- Check phase to re-audit the same period
Correct answer: Act phase to take corrective actions and improve
When Check reveals underperformance, the Act phase initiates corrective actions to address root causes.
Question 7: Which ISO/IEC 27000 series standard specifically defines the PDCA model's application to information security management?
- ISO/IEC 27002
- ISO/IEC 27005
- ISO/IEC 27001 (Correct answer)
- ISO/IEC 27003
Correct answer: ISO/IEC 27001
ISO/IEC 27001 is the ISMS requirements standard that formally applies the PDCA model to information security management.
In the PDCA model, what is the primary risk of skipping the 'Check' phase?