โ† All ISO 27000 Foundation Certification Flashcard Decks

Scope of the ISMS Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Scope of the ISMS flashcards as text
  1. Which document formally records the boundaries and applicability of an organization's ISMS?

    Answer: Scope statement

    The ISMS scope statement is the document that formally defines the boundaries and applicability of the information security management system.

  2. An organization decides to exclude its HR department from the ISMS scope. What must it do according to ISO 27001?

    Answer: Justify the exclusion and ensure it does not affect security obligations

    ISO 27001 requires organizations to justify any exclusions and ensure those exclusions do not affect the ability to achieve intended outcomes or compliance obligations.

  3. Which of the following best describes an 'interested party' in the context of ISMS scope?

    Answer: Any person or organization that can affect or be affected by the ISMS

    Interested parties include any person or organization that can affect, be affected by, or perceive themselves to be affected by the ISMS.

  4. A company's ISMS scope includes its main office but not its remote data center operated by a third party. What risk does this create?

    Answer: Information security risks from the data center may not be managed under the ISMS

    Excluding a third-party data center means risks originating there are outside the ISMS framework, potentially leaving significant vulnerabilities unmanaged.

  5. Context of the organization, as required by ISO 27001 Clause 4, influences ISMS scope by identifying:

    Answer: Internal and external issues relevant to information security

    Clause 4 requires organizations to determine internal and external issues that are relevant to the ISMS purpose and that affect its ability to achieve intended outcomes.

  6. When defining ISMS scope, which factor is LEAST relevant to consider?

    Answer: The organization's branding and marketing strategy

    Branding and marketing strategy are business concerns that do not directly influence the boundaries of an information security management system.

  7. Which statement about ISMS scope documentation is correct per ISO 27001?

    Answer: The scope must be available as documented information

    ISO 27001 requires that the ISMS scope be maintained as documented information that is available to relevant parties.