ISMS Implementation and Operation Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 ISMS Implementation and Operation flashcards as text
Which statement correctly describes the relationship between risk assessment and risk treatment in an operational ISMS?
Answer: Risk assessment identifies and evaluates risks; risk treatment decides how to address them
Risk assessment produces a risk profile, which then informs the risk treatment process that selects and implements appropriate controls.
When an organization changes its IT infrastructure significantly, what ISMS action is immediately required?
Answer: Conduct a risk reassessment to account for changes in the threat landscape
Significant changes trigger a reassessment of risks because new assets, technologies, or configurations may introduce previously unidentified threats.
What is the role of 'internal communication' in an operational ISMS?
Answer: It ensures relevant information security matters are communicated internally on time
ISO 27001 Clause 7.4 requires the organization to determine what, when, how, and to whom information security information must be communicated internally.
A company decides to accept a risk rather than apply a control. What must be documented?
Answer: A formal risk acceptance decision approved by the risk owner
Risk acceptance must be formally documented and approved by the designated risk owner as part of the risk treatment record.
Which metric would best demonstrate the operational effectiveness of an ISMS access control process?
Answer: Percentage of access rights reviewed and revoked within the required timeframe
Measuring timely access reviews and revocations directly indicates whether the access control process is functioning as intended.
What does 'continual improvement' of the ISMS primarily rely on?
Answer: Findings from audits, nonconformities, monitoring results, and management review outputs
Continual improvement draws on audit findings, incident data, nonconformities, performance measurements, and management review decisions.
Under ISO 27001, what happens if the ISMS scope changes after initial certification?
Answer: The organization must review and update the scope statement and assess impact on the ISMS
Scope changes require the organization to update the scope document, reassess risks affected by the change, and adjust controls accordingly.