โ† All ISO 27000 Foundation Certification Flashcard Decks

Governance and Leadership Flashcards

6 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Governance and Leadership flashcards as text
  1. In ISO 27001 terminology, who are 'interested parties'?

    Answer: Persons or organizations that can affect or be affected by the ISMS

    Interested parties (stakeholders) are any persons or organizations whose needs and expectations must be considered when establishing the ISMS.

  2. What is the purpose of assigning information security roles and responsibilities in ISO 27001?

    Answer: To ensure accountability and clarity in protecting information assets

    Clearly defined roles and responsibilities ensure that every aspect of information security is owned, monitored, and actioned by specific individuals.

  3. Which ISO standard provides specific guidance on information security governance at the enterprise level?

    Answer: ISO 27014

    ISO 27014 provides guidance on the governance of information security, addressing the roles of the governing body and executive management.

  4. What does 'organizational context' mean in the ISO 27001 framework?

    Answer: Understanding internal and external factors that influence the ISMS

    Organizational context requires identifying internal and external issues, as well as interested parties, that are relevant to the organization's information security objectives.

  5. How should information security responsibilities be communicated to employees according to ISO 27001?

    Answer: Through documented policies, procedures, and awareness programs

    ISO 27001 requires that roles and responsibilities be documented and communicated through formal policies, procedures, and ongoing awareness activities.

  6. What is the significance of the 'Statement of Applicability' (SoA) in governance terms?

    Answer: It records which Annex A controls are applicable and justifies inclusions and exclusions

    The SoA is a critical governance document that maps Annex A controls to the organization's risk treatment decisions, explaining why each control is included or excluded.