ISO 27000 Foundation Certification Governance and Leadership 1 — Questions and Answers
Question 1: According to ISO 27001, who holds ultimate accountability for the ISMS?
- The IT department
- Top management (Correct answer)
- The information security officer
- External auditors
Correct answer: Top management
ISO 27001 requires top management to take ultimate accountability for establishing, implementing, and maintaining the ISMS.
Question 2: Which document formally expresses an organization's commitment to information security under ISO 27001?
- Risk register
- Statement of applicability
- Information security policy (Correct answer)
- Business continuity plan
Correct answer: Information security policy
The information security policy is the top-level document that formally communicates management's commitment and direction for information security.
Question 3: What must the information security policy be in accordance with, according to ISO 27001?
- Industry benchmarks only
- The organization's strategic direction (Correct answer)
- Government regulations exclusively
- International audit standards
Correct answer: The organization's strategic direction
ISO 27001 requires that the information security policy be appropriate to and aligned with the organization's overall strategic direction.
Question 4: Who is responsible for defining the scope of the ISMS in ISO 27001?
- External consultants
- The IT security team
- Top management (Correct answer)
- ISO certification body
Correct answer: Top management
Top management is responsible for determining and approving the boundaries and applicability of the ISMS, i.e., its scope.
Question 5: Which of the following is a key leadership activity required by ISO 27001?
- Performing penetration tests
- Ensuring integration of ISMS requirements into business processes (Correct answer)
- Writing firewall rules
- Conducting employee background checks
Correct answer: Ensuring integration of ISMS requirements into business processes
ISO 27001 requires top management to ensure that ISMS requirements are integrated into the organization's business processes.
Question 6: How must an organization's information security objectives relate to its overall business objectives?
- They must be completely independent
- They must be aligned and consistent (Correct answer)
- They are set solely by the IT team
- They only apply to technical systems
Correct answer: They must be aligned and consistent
ISO 27001 requires information security objectives to be consistent with and support the overall organizational objectives.
According to ISO 27001, who holds ultimate accountability for the ISMS?