Scope of the ISMS Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Scope of the ISMS flashcards as text
Which ISO 27001 clause specifically requires the organization to determine the scope of the ISMS?
Answer: Clause 4 – Context of the organization
Clause 4.3 of ISO 27001 explicitly requires the organization to determine the boundaries and applicability of the ISMS to establish its scope.
A software firm includes its development team in the ISMS scope but excludes the sales team. Customer contracts handled by sales contain sensitive data. What should the firm do?
Answer: Extend the scope to include sales or implement compensating controls for customer data handled by sales
When sensitive data is processed outside the ISMS scope, the organization must either expand the scope or ensure equivalent controls exist for that data.
In the PDCA (Plan-Do-Check-Act) cycle applied to the ISMS, at which stage is the scope initially established?
Answer: Plan
ISMS scope is established during the Plan stage, along with risk assessment, objectives, and the selection of controls.
An organization reviews its ISMS scope annually and expands it to include a newly acquired subsidiary. What does this reflect?
Answer: Continual improvement and adaptation of the ISMS to changing organizational context
Updating the ISMS scope in response to organizational changes reflects the continual improvement principle central to ISO 27001.
Which of the following is an example of an internal issue that could influence ISMS scope?
Answer: The organization's culture and existing security maturity
Internal issues such as organizational culture, existing security practices, and maturity levels directly influence what is feasible and appropriate to include in the ISMS scope.
A financial services firm's ISMS scope statement reads: 'All systems supporting retail banking operations at the New York headquarters.' What type of boundary does this represent?
Answer: Functional and physical boundary
The scope statement defines both a functional boundary (retail banking operations) and a physical boundary (New York headquarters).
According to ISO 27001, when should the ISMS scope be reviewed?
Answer: Whenever there are significant changes to the organization or its context
The ISMS scope should be reviewed whenever significant organizational or contextual changes occur that may affect the boundaries or applicability of the ISMS.