ISO 27000 Foundation ISO 27000 Family of Standards Questions and Answers — Questions and Answers
Question 1: An information security manager is using Annex A of ISO/IEC 27001 to select appropriate controls. For a specific control, such as 'A.5.23 Information security for use of cloud services', they require more detailed implementation guidance. Which standard in the ISO 27000 family provides this detailed guidance for the controls listed in Annex A?
- ISO/IEC 27000
- ISO/IEC 27002 (Correct answer)
- ISO/IEC 27005
- ISO/IEC 27001
Correct answer: ISO/IEC 27002
ISO/IEC 27001 lists the controls in Annex A, but it does not provide detailed implementation guidance. ISO/IEC 27002, titled 'Information security, cybersecurity and privacy protection — Information security controls', serves as a code of practice and provides a detailed reference set of generic information security controls, including implementation guidance for each control in Annex A.
Question 2: The ISO 27001 standard is structured around the Plan-Do-Check-Act (PDCA) model for continual improvement. Which of the following clauses are primarily associated with the 'Check' phase of the cycle?
- Clause 4 (Context of the organization) and Clause 5 (Leadership)
- Clause 7 (Support) and Clause 8 (Operation)
- Clause 9 (Performance evaluation) (Correct answer)
- Clause 10 (Improvement)
Correct answer: Clause 9 (Performance evaluation)
The 'Check' phase of the PDCA cycle involves monitoring and reviewing the performance of the ISMS. Clause 9, 'Performance evaluation', directly addresses this by requiring the organization to monitor, measure, analyze, and evaluate the ISMS, conduct internal audits, and perform management reviews.
Question 3: As part of an ISO 27001 implementation, the Chief Executive Officer (CEO) of an organization publicly endorses the new information security policy and ensures that sufficient budget and personnel are allocated for the ISMS project. Which specific leadership responsibility from ISO 27001 is the CEO primarily demonstrating?
- Ensuring the integration of ISMS requirements into the organization’s processes and providing necessary resources. (Correct answer)
- Conducting the detailed information security risk assessment.
- Writing the specific procedures for access control.
- Performing the daily backup and recovery operations.
Correct answer: Ensuring the integration of ISMS requirements into the organization’s processes and providing necessary resources.
ISO 27001 Clause 5.1 ('Leadership and commitment') requires top management to demonstrate their commitment. This includes ensuring the information security policy and objectives are established, ensuring the integration of ISMS requirements into the organization's processes, and ensuring that the resources needed for the ISMS are available. The CEO's actions directly align with these high-level responsibilities. The other options are operational tasks typically delegated to security or IT teams.
Question 4: An organization is establishing its ISMS according to ISO 27001 and is determining its 'interested parties' as required by Clause 4.2. Which of the following would be the LEAST likely to be considered a relevant interested party with requirements pertinent to the ISMS?
- A government regulatory body that enforces data protection laws.
- A major customer who requires security assurances in their service contract.
- The company's shareholders who are concerned about business continuity.
- A competitor company operating in the same market. (Correct answer)
Correct answer: A competitor company operating in the same market.
Interested parties are individuals or organizations that can affect, be affected by, or perceive themselves to be affected by the organization's ISMS. Regulators, customers, and shareholders have direct requirements and expectations for the organization's information security. While a competitor is part of the business environment, they do not typically have direct, legitimate requirements *for* the organization's ISMS that need to be addressed within its framework.
Question 5: A multinational corporation has an established ISMS certified to ISO/IEC 27001. To comply with evolving global data privacy regulations, the company wants to enhance its ISMS to specifically manage and protect Personally Identifiable Information (PII). Which ISO 27000 family standard provides a framework for a Privacy Information Management System (PIMS) as an extension to an ISMS?
- ISO/IEC 27017
- ISO/IEC 27032
- ISO/IEC 27701 (Correct answer)
- ISO/IEC 27005
Correct answer: ISO/IEC 27701
ISO/IEC 27701 is designed as a privacy extension to ISO/IEC 27001 and ISO/IEC 27002. It specifies requirements and provides guidance for establishing, implementing, and maintaining a Privacy Information Management System (PIMS), helping organizations manage PII and comply with privacy regulations. ISO/IEC 27017 is for cloud security, 27032 for cybersecurity, and 27005 for risk management.
Question 6: According to the vocabulary defined in the ISO 27000 family, which statement BEST describes the relationship between a threat, a vulnerability, and an asset?
- A vulnerability is a potential cause of an incident that may result in harm to an asset.
- A threat is a potential cause of an incident that may harm an asset by exploiting a vulnerability. (Correct answer)
- A threat exploits an asset to cause harm to a vulnerability.
- An asset is a weakness that can be exploited by a threat.
Correct answer: A threat is a potential cause of an incident that may harm an asset by exploiting a vulnerability.
The standard risk model is that a threat (a potential cause of an incident) can exploit a vulnerability (a weakness) to cause harm to an asset (something of value). For a risk to exist, all three elements are typically present. Option B correctly places these three components in their logical relationship.
An information security manager is using Annex A of ISO/IEC 27001 to select appropriate controls.
For a specific control, such as 'A.5.23 Information security for use of cloud services', they require more detailed implementation guidance.
Which standard in the ISO 27000 family provides this detailed guidance for the controls listed in Annex A?