Mixed Deck — All ISO 27000 Foundation Certification Topics Flashcards
100 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All ISO 27000 Foundation Certification Topics flashcards as text
What is 'segregation of duties' as referenced in ISO 27001 controls?
Answer: Dividing tasks so no single person controls all aspects of a critical process
Segregation of duties reduces the risk of fraud or error by ensuring no single individual can complete a sensitive process without oversight from another.
What is an escalation procedure in the context of incident management?
Answer: A defined path for elevating an incident to higher management or specialists when needed
Escalation procedures define when and how an incident should be elevated to higher authority or specialized teams when it exceeds the current responder's ability or authority to handle it.
A financial services company is implementing an Information Security Management System (ISMS). They are currently identifying anything that has value to the organization, including customer data, proprietary software, and servers. In the context of ISO/IEC 27000, what is the correct term for these items?
Answer: Assets
ISO/IEC 27000 defines an 'asset' as anything that has value to the organization. This includes data, software, hardware, and services. Risks are the effect of uncertainty on objectives, vulnerabilities are weaknesses, and controls are measures that modify risk.
Which of the following best describes 'non-repudiation' in information security?
Answer: Ensuring a party cannot deny performing an action
Non-repudiation ensures that a party cannot deny having sent or received information or performed an action.
Which of the following scenarios BEST illustrates the risk treatment option of risk modification?
Answer: Installing a firewall to reduce the likelihood of unauthorized network access
Installing a firewall modifies (reduces) the risk by lowering the likelihood of a threat exploiting a vulnerability.
What has to be done as part of the monitoring, measuring, analysis, and evaluation process?
Answer: Evaluate the effectiveness of the ISMS
Clause 9.1 of ISO 27001, 'Monitoring, measurement, analysis and evaluation,' explicitly requires the organization to evaluate the information security performance and the effectiveness of the ISMS. This is a crucial step to ensure that the implemented controls and processes are achieving their intended outcomes and adequately protecting information assets.
What is the role of management review outputs in the ISMS improvement process?
Answer: They include decisions and actions related to continual improvement opportunities
ISO 27001 Clause 9.3 states that management review outputs must include decisions and actions related to continual improvement opportunities and any need for changes to the ISMS.
"The only emphasis of ISO 27001:2013 is the protection of personal information."
Answer: False
This statement is false. While the protection of personal information is often a critical aspect addressed by an ISMS, ISO 27001's scope is much broader. It aims to protect all types of information and information assets from a wide range of threats, ensuring confidentiality, integrity, and availability for the entire organization, not just personal data.
The ISO 27001:2022 standard restructured the Annex A controls from 14 domains into four main themes. Which theme encompasses the broadest, highest-level controls concerning information security governance, policies, and risk management?
Answer: Organizational Controls
The Organizational Controls theme serves as the foundation for the ISMS. It includes the broadest controls that define the organization's overall approach to information security, such as policies, roles and responsibilities, asset management, and supplier relationships.
A financial institution is conducting a security review. They are evaluating the effectiveness of their employee security awareness training, background verification screening for new hires, and the formal disciplinary process for security violations. Which Annex A control theme are they focusing on?
Answer: People Controls
The controls being evaluated—security awareness training, screening, and disciplinary processes—are all centered on managing security risks related to human factors. The People Controls theme specifically covers the entire employee lifecycle to mitigate risks arising from human error, negligence, or malicious intent.
What is the main goal of the risk communication and consultation process in ISO 27005?
Answer: To ensure stakeholders are informed and their input is considered throughout risk management
Risk communication and consultation ensures that stakeholders share information and contribute to risk decisions throughout the process.
Under ISO 27001, who holds ultimate accountability for the ISMS?
Answer: Top management
ISO 27001 clause 5 (Leadership) places accountability for the ISMS on top management of the organization.
Which of the four risk treatment options involves sharing the risk with another party?
Answer: Risk transfer
Risk transfer (also called risk sharing) involves passing the financial or operational impact of a risk to another party, such as an insurer.
According to ISO 27001, which of the following is the primary purpose of monitoring, measurement, analysis, and evaluation of the ISMS?
Answer: To evaluate information security performance and the effectiveness of the ISMS.
ISO 27001 Clause 9.1 requires the organization to evaluate the information security performance and the effectiveness of the Information Security Management System (ISMS). This process provides the data needed for management reviews and continual improvement, ensuring the ISMS is achieving its intended outcomes.
How does ISO 27001 define 'competence' in the context of ISMS personnel?
Answer: The ability to apply knowledge and skills to achieve intended results
Competence means having the necessary education, training, or experience to perform information security roles effectively.
Which ISO/IEC 27000 series standard specifically defines the PDCA model's application to information security management?
Answer: ISO/IEC 27001
ISO/IEC 27001 is the ISMS requirements standard that formally applies the PDCA model to information security management.
How should an organization handle a situation where two ISMS controls conflict with each other operationally?
Answer: Document the conflict, assess the risk, and implement a compensating control or resolution
Control conflicts must be documented, risk-assessed, and resolved through compensating controls or process adjustments to maintain security posture.
What is the difference between a threat and a threat agent in ISO 27000?
Answer: A threat is the potential for harm; a threat agent is the entity that exploits a vulnerability
A threat is the potential cause of an incident, while the threat agent is the specific individual, group, or force that carries out the threat.
An organization decides to purchase cyber-insurance to address a specific information security risk. Which risk treatment option does this represent?
Answer: Risk sharing
Risk sharing (also called risk transfer) involves distributing the financial burden of a risk to a third party such as an insurer.
What does 'asset classification' involve under ISO 27001?
Answer: Categorizing assets based on their value and sensitivity to apply appropriate protection
Asset classification assigns labels such as public, internal, confidential, or secret to determine the level of protection each asset requires.