ISMS Implementation and Operation Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 ISMS Implementation and Operation flashcards as text
What distinguishes an 'information security objective' from a general security policy statement?
Answer: Objectives are specific, measurable targets aligned with the security policy
Information security objectives must be measurable (where practical), consistent with the policy, and monitored for progress.
During ISMS implementation, who holds ultimate accountability for accepting residual risk?
Answer: Top management or designated risk owners
Risk owners, approved by top management, are accountable for accepting residual risk after treatment options have been applied.
What does the ISMS 'Plan-Do-Check-Act' cycle emphasize during the 'Do' phase?
Answer: Implementing and operating the ISMS controls as planned
The 'Do' phase involves executing the plans made in 'Plan,' putting controls, processes, and procedures into practice.
Which of the following is a valid risk treatment option under ISO 27001?
Answer: Risk modification through applying security controls
ISO 27001 risk treatment options include modification (applying controls), avoidance, sharing/transfer, and retention โ not elimination or creation.
A new employee joins a department that processes confidential customer data. What ISMS onboarding step is most critical?
Answer: Providing information security awareness training before granting data access
New employees must receive security awareness training aligned to their role before handling sensitive information, per ISO 27001 Clause 7.3.
What is the purpose of maintaining an 'asset inventory' during ISMS operation?
Answer: To identify assets within scope so appropriate controls can be applied
An asset inventory identifies what information assets exist within scope, enabling the organization to assign ownership and apply appropriate protections.
How should an organization handle a situation where two ISMS controls conflict with each other operationally?
Answer: Document the conflict, assess the risk, and implement a compensating control or resolution
Control conflicts must be documented, risk-assessed, and resolved through compensating controls or process adjustments to maintain security posture.