โ† All ISO 27000 Foundation Certification Flashcard Decks

Governance and Leadership Flashcards

6 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Governance and Leadership flashcards as text
  1. What must be included in an information security policy according to ISO 27001?

    Answer: Objectives and a commitment to satisfying applicable requirements

    ISO 27001 specifies that the information security policy must include security objectives or a framework for setting them and a commitment to satisfying applicable requirements.

  2. How frequently does ISO 27001 require information security objectives to be reviewed?

    Answer: At planned intervals and when significant changes occur

    ISO 27001 requires objectives to be reviewed at planned intervals and updated when the organization's context or risks change significantly.

  3. What distinguishes an information security policy from an information security procedure?

    Answer: A policy states management's intent and direction; a procedure describes specific steps to follow

    A policy communicates high-level management intent and principles, whereas a procedure details the specific steps employees must follow to comply with the policy.

  4. Why must the information security policy be available to interested parties according to ISO 27001?

    Answer: To demonstrate transparency and ensure stakeholders understand the organization's security stance

    Making the policy available to interested parties ensures transparency and demonstrates the organization's commitment to information security to customers, partners, and regulators.

  5. What is meant by 'continual improvement' in the context of ISO 27001 governance?

    Answer: Recurring activities to enhance ISMS performance and effectiveness over time

    Continual improvement means the organization systematically reviews and enhances its ISMS processes, controls, and policies to better meet security objectives over time.

  6. Which concept ensures that information security governance decisions are traceable back to accountable individuals?

    Answer: Accountability

    Accountability in governance means that every security decision and action can be traced to a specific responsible individual, supporting audit and oversight.