ISO 27000 Foundation Certification The PDCA Cycle 2 — Questions and Answers
Question 1: In the context of ISO/IEC 27001, which PDCA phase is responsible for establishing the information security policy?
- Do
- Plan (Correct answer)
- Check
- Act
Correct answer: Plan
The Plan phase establishes the ISMS scope, policy, objectives, and risk assessment processes.
Question 2: An organization discovers during an internal audit that its incident response procedures are not being followed. Which PDCA phase does this discovery belong to?
- Plan
- Do
- Check (Correct answer)
- Act
Correct answer: Check
Internal audits and reviews are Check phase activities that measure whether implemented controls are effective.
Question 3: What is the primary purpose of the 'Act' phase in the PDCA cycle within an ISMS?
- Deploying new security tools
- Implementing the risk treatment plan
- Taking corrective and preventive actions to continually improve the ISMS (Correct answer)
- Training employees on security awareness
Correct answer: Taking corrective and preventive actions to continually improve the ISMS
The Act phase focuses on continual improvement by addressing nonconformities and implementing corrective actions.
Question 4: Which ISO/IEC 27001 clause activity most directly aligns with the 'Do' phase of PDCA?
- Clause 6: Planning
- Clause 9: Performance Evaluation
- Clause 8: Operation (Correct answer)
- Clause 10: Improvement
Correct answer: Clause 8: Operation
Clause 8 (Operation) covers implementing and controlling processes, which corresponds to the Do phase.
Question 5: How does the PDCA cycle support the concept of continual improvement in an ISMS?
- By ensuring the ISMS is only reviewed once per year
- By creating a feedback loop where findings from Check and Act phases refine future Plan phases (Correct answer)
- By preventing any changes to security controls once deployed
- By limiting improvement to technical controls only
Correct answer: By creating a feedback loop where findings from Check and Act phases refine future Plan phases
PDCA creates an iterative feedback loop where audit findings and corrective actions continuously feed back into better planning.
Question 6: During which PDCA phase would an organization conduct a risk assessment for a new cloud migration project?
- Do
- Check
- Act
- Plan (Correct answer)
Correct answer: Plan
Risk assessment is a planning activity that must be completed before implementing new systems or changes.
Question 7: A company updates its access control policy after finding unauthorized access during a review. This update is an example of which PDCA phase?
- Plan
- Do
- Check
- Act (Correct answer)
Correct answer: Act
Updating policies and controls in response to audit findings is a corrective action belonging to the Act phase.
In the context of ISO/IEC 27001, which PDCA phase is responsible for establishing the information security policy?