โ† All ISO 27000 Foundation Certification Flashcard Decks

Prior Knowledge Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Prior Knowledge flashcards as text
  1. Which of the following must be documented (in Clause 6) according to ISO 27001:2013?

    Answer: Risk assessment

    Clause 6 of ISO 27001:2013, 'Planning,' explicitly requires the organization to establish and maintain documented information for its information security risk assessment process and the results of the information security risk assessment. While risk treatment is also a critical part of the planning phase, the process and outcomes of the risk assessment itself are specifically mandated to be documented.

  2. Where in the standard is a reference to controls and control goals to be found?

    Answer: Annex A

    Annex A of ISO/IEC 27001 provides a comprehensive reference list of information security controls and control objectives. These controls are derived from ISO/IEC 27002 and serve as a guide for organizations to select and implement appropriate measures to address identified risks. Organizations must consider these controls when developing their Statement of Applicability.

  3. The management system's scope must be kept up to date as written information.

    Answer: True

    ISO 27001 requires that the scope of the Information Security Management System (ISMS) be defined and maintained as documented information. This ensures clarity regarding which parts of the organization, its processes, and information assets are covered by the ISMS. Keeping it up to date is crucial for the ISMS to remain relevant and effective.

  4. "The only emphasis of ISO 27001:2013 is the protection of personal information."

    Answer: False

    This statement is false. While the protection of personal information is often a critical aspect addressed by an ISMS, ISO 27001's scope is much broader. It aims to protect all types of information and information assets from a wide range of threats, ensuring confidentiality, integrity, and availability for the entire organization, not just personal data.

  5. What must the company create?

    Answer: Statement of applicability

    The Statement of Applicability (SoA) is a mandatory document under ISO 27001. It lists all controls from Annex A that are relevant to the organization's ISMS, along with justifications for their inclusion or exclusion, and a description of how they are implemented. This document demonstrates how the organization has addressed the identified risks and chosen its controls.

  6. What does "fulfillment of a requirement" mean in ISO 27001:2013?

    Answer: Conformity

    In the context of ISO standards, 'conformity' specifically refers to the fulfillment of a requirement. When an organization's Information Security Management System (ISMS) meets all the requirements outlined in ISO 27001, it is considered to be in conformity with the standard. This term is precise for demonstrating adherence to the standard's clauses.

  7. Which does not fall under senior management's purview?

    Answer: Appoint a management representative

    ISO 27001:2013 (and subsequent versions) does not explicitly require senior management to appoint a single 'management representative' for the ISMS. While senior management is responsible for establishing the information security policy and promoting continual improvement, the standard focuses on assigning responsibilities and authorities for the ISMS rather than mandating a specific representative role.