ISO 27000 Foundation Certification The PDCA Cycle 5 — Questions and Answers
Question 1: An organization has completed its first full PDCA cycle for its ISMS. What should it do next?
- Disband the ISMS team since implementation is complete
- Archive all documents and start fresh with a new framework
- Begin a new PDCA cycle incorporating lessons learned from the first cycle (Correct answer)
- Wait for the next security incident before reviewing
Correct answer: Begin a new PDCA cycle incorporating lessons learned from the first cycle
PDCA is a continual cycle; after Act, the organization feeds improvements back into a new Plan phase.
Question 2: Which of the following is the most accurate description of the 'Do' phase in an ISMS PDCA cycle?
- Measuring and monitoring the effectiveness of controls
- Implementing and operating the controls selected during planning (Correct answer)
- Identifying and assessing information security risks
- Taking corrective actions to fix identified nonconformities
Correct answer: Implementing and operating the controls selected during planning
The Do phase is where planned controls and processes are put into operation throughout the organization.
Question 3: A financial firm applies PDCA to its ISMS after a data breach. In which phase would root cause analysis of the breach be performed?
- Plan
- Do
- Check (Correct answer)
- Act
Correct answer: Check
Investigating incidents and performing root cause analysis are Check phase activities that evaluate what went wrong.
Question 4: Which of the following PDCA activities directly supports ISO/IEC 27001 Clause 10 (Improvement)?
- Plan: Defining information security objectives
- Do: Implementing risk treatments
- Check: Conducting internal audits
- Act: Taking corrective actions and pursuing continual improvement (Correct answer)
Correct answer: Act: Taking corrective actions and pursuing continual improvement
ISO/IEC 27001 Clause 10 maps directly to the Act phase, covering nonconformity, corrective action, and continual improvement.
Question 5: What is the significance of 'preventive actions' in the PDCA cycle as applied to an ISMS?
- They are only relevant during the Do phase
- They address potential nonconformities before they occur, applied during Plan and Act phases (Correct answer)
- They replace the need for corrective actions
- They are performed exclusively by external auditors
Correct answer: They address potential nonconformities before they occur, applied during Plan and Act phases
Preventive actions anticipate and eliminate causes of potential nonconformities, typically planned in the Plan phase and reinforced in Act.
Question 6: In a PDCA cycle for ISMS, which output from the 'Act' phase becomes an input to the next 'Plan' phase?
- Completed employee training records
- Corrective action results and improvement proposals (Correct answer)
- Finalized audit schedules
- Implemented technical controls
Correct answer: Corrective action results and improvement proposals
The results of corrective actions and improvement decisions from Act feed directly into the next iteration of planning.
Question 7: Which of the following scenarios illustrates the 'Check' phase of PDCA in an ISO 27001 ISMS?
- Developing a business impact analysis for a new product line
- Configuring firewall rules based on the risk treatment plan
- Reviewing security metrics dashboards to assess control effectiveness (Correct answer)
- Updating the access control policy after a security incident
Correct answer: Reviewing security metrics dashboards to assess control effectiveness
Reviewing metrics and dashboards to assess whether controls are working effectively is a core Check phase activity.
An organization has completed its first full PDCA cycle for its ISMS.
What should it do next?