Free ISO 27000 Foundation Certification Prior Knowledge Questions and Answers — Questions and Answers
Question 1: Which of the following must be documented (in Clause 6) according to ISO 27001:2013?
- Risk treatment
- Risk assessment (Correct answer)
- None of the above
Correct answer: Risk assessment
Clause 6 of ISO 27001:2013, 'Planning,' explicitly requires the organization to establish and maintain documented information for its information security risk assessment process and the results of the information security risk assessment. While risk treatment is also a critical part of the planning phase, the process and outcomes of the risk assessment itself are specifically mandated to be documented.
Question 2: Where in the standard is a reference to controls and control goals to be found?
- Annex A (Correct answer)
- Annex SL
- Clause 9 Performance evaluation
Correct answer: Annex A
Annex A of ISO/IEC 27001 provides a comprehensive reference list of information security controls and control objectives. These controls are derived from ISO/IEC 27002 and serve as a guide for organizations to select and implement appropriate measures to address identified risks. Organizations must consider these controls when developing their Statement of Applicability.
Question 3: The management system's scope must be kept up to date as written information.
- True (Correct answer)
- False
Correct answer: True
ISO 27001 requires that the scope of the Information Security Management System (ISMS) be defined and maintained as documented information. This ensures clarity regarding which parts of the organization, its processes, and information assets are covered by the ISMS. Keeping it up to date is crucial for the ISMS to remain relevant and effective.
Question 4: "The only emphasis of ISO 27001:2013 is the protection of personal information."
- True
- False (Correct answer)
Correct answer: False
This statement is false. While the protection of personal information is often a critical aspect addressed by an ISMS, ISO 27001's scope is much broader. It aims to protect all types of information and information assets from a wide range of threats, ensuring confidentiality, integrity, and availability for the entire organization, not just personal data.
Question 5: What must the company create?
- Statement of control
- Statement of implementation
- Statement of applicability (Correct answer)
Correct answer: Statement of applicability
The Statement of Applicability (SoA) is a mandatory document under ISO 27001. It lists all controls from Annex A that are relevant to the organization's ISMS, along with justifications for their inclusion or exclusion, and a description of how they are implemented. This document demonstrates how the organization has addressed the identified risks and chosen its controls.
Question 6: What does "fulfillment of a requirement" mean in ISO 27001:2013?
- Compliance
- Conformity (Correct answer)
- None of the above
Correct answer: Conformity
In the context of ISO standards, 'conformity' specifically refers to the fulfillment of a requirement. When an organization's Information Security Management System (ISMS) meets all the requirements outlined in ISO 27001, it is considered to be in conformity with the standard. This term is precise for demonstrating adherence to the standard's clauses.
Question 7: Which does not fall under senior management's purview?
- Appoint a management representative (Correct answer)
- Promoting continual improvement
- Establish an information security policy
Correct answer: Appoint a management representative
ISO 27001:2013 (and subsequent versions) does not explicitly require senior management to appoint a single 'management representative' for the ISMS. While senior management is responsible for establishing the information security policy and promoting continual improvement, the standard focuses on assigning responsibilities and authorities for the ISMS rather than mandating a specific representative role.
Which of the following must be documented (in Clause 6) according to ISO 27001:2013?