Free ISO 27000 Foundation ISMS Fundamentals and Vocabulary Questions and Answers — Questions and Answers
Question 1: According to ISO/IEC 27000, which of the following BEST defines 'confidentiality' as a core principle of information security?
- The property of accuracy and completeness of information.
- The property that information is not made available or disclosed to unauthorized individuals, entities, or processes. (Correct answer)
- The property of being accessible and usable upon demand by an authorized entity.
- The property of ensuring that the actions of an entity can be traced uniquely to that entity.
Correct answer: The property that information is not made available or disclosed to unauthorized individuals, entities, or processes.
ISO/IEC 27000:2018 explicitly defines confidentiality as 'the property that information is not made available or disclosed to unauthorized individuals, entities, or processes'. This is a fundamental component of the CIA triad, which forms the basis of information security.
Question 2: A financial company identifies that a disgruntled former employee still possesses network access credentials. In the context of an ISMS based on ISO 27000, what does this situation primarily represent?
- A risk
- An asset
- A control
- A threat (Correct answer)
Correct answer: A threat
ISO/IEC 27000 defines a threat as a 'potential cause of an unwanted incident, which may result in harm to a system or organization'. The disgruntled former employee with credentials is the potential cause of an incident; they are the threat agent.
Question 3: Which standard in the ISO 27000 family provides the overview, fundamental principles, and vocabulary for Information Security Management Systems (ISMS)?
- ISO/IEC 27001
- ISO/IEC 27005
- ISO/IEC 27000 (Correct answer)
- ISO/IEC 27002
Correct answer: ISO/IEC 27000
ISO/IEC 27000 is the foundational standard in the series. It provides a comprehensive overview of ISMS, introduces key concepts, and, most importantly, establishes the formal terms and definitions used throughout the entire ISO/IEC 27000 family of standards.
Question 4: An organization's server room lacks a fire suppression system. According to the vocabulary of ISO 27000, this deficiency is best described as a(n):
- Impact
- Threat
- Risk
- Vulnerability (Correct answer)
Correct answer: Vulnerability
A vulnerability is defined as a 'weakness of an asset or control that can be exploited by one or more threats'. The absence of a fire suppression system is a weakness in the physical protection of the server room asset, which could be exploited by a threat (i.e., a fire).
Question 5: What are the three core components of the CIA triad, as defined in ISO/IEC 27000, that an ISMS is designed to preserve?
- Control, Integrity, and Audit
- Confidentiality, Integrity, and Availability (Correct answer)
- Continuity, Information, and Assurance
- Compliance, Integrity, and Administration
Correct answer: Confidentiality, Integrity, and Availability
ISO/IEC 27000 defines the three fundamental principles of information security as the CIA triad: Confidentiality, Integrity, and Availability. These three principles are the cornerstone of an ISMS and represent the primary objectives for protecting information assets.
Question 6: Which of the following is the PRIMARY purpose of an Information Security Management System (ISMS) as described in the ISO 27000 series?
- To implement the latest cybersecurity technology and software.
- To establish, implement, maintain, and continually improve information security within an organization. (Correct answer)
- To guarantee that the organization will never experience a security breach.
- To satisfy the requirements of a single, specific data protection regulation.
Correct answer: To establish, implement, maintain, and continually improve information security within an organization.
The ISO 27000 family of standards describes an ISMS as a systematic approach for establishing, implementing, operating, monitoring, reviewing, maintaining, and improving an organization's information security to achieve business objectives. It is a continuous, process-based approach, not just a one-time implementation of technology.
According to ISO/IEC 27000, which of the following BEST defines 'confidentiality' as a core principle of information security?