โ† All ISO 27000 Foundation Certification Flashcard Decks

The PDCA Cycle Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 The PDCA Cycle flashcards as text
  1. In the context of ISO/IEC 27001, which PDCA phase is responsible for establishing the information security policy?

    Answer: Plan

    The Plan phase establishes the ISMS scope, policy, objectives, and risk assessment processes.

  2. An organization discovers during an internal audit that its incident response procedures are not being followed. Which PDCA phase does this discovery belong to?

    Answer: Check

    Internal audits and reviews are Check phase activities that measure whether implemented controls are effective.

  3. What is the primary purpose of the 'Act' phase in the PDCA cycle within an ISMS?

    Answer: Taking corrective and preventive actions to continually improve the ISMS

    The Act phase focuses on continual improvement by addressing nonconformities and implementing corrective actions.

  4. Which ISO/IEC 27001 clause activity most directly aligns with the 'Do' phase of PDCA?

    Answer: Clause 8: Operation

    Clause 8 (Operation) covers implementing and controlling processes, which corresponds to the Do phase.

  5. How does the PDCA cycle support the concept of continual improvement in an ISMS?

    Answer: By creating a feedback loop where findings from Check and Act phases refine future Plan phases

    PDCA creates an iterative feedback loop where audit findings and corrective actions continuously feed back into better planning.

  6. During which PDCA phase would an organization conduct a risk assessment for a new cloud migration project?

    Answer: Plan

    Risk assessment is a planning activity that must be completed before implementing new systems or changes.

  7. A company updates its access control policy after finding unauthorized access during a review. This update is an example of which PDCA phase?

    Answer: Act

    Updating policies and controls in response to audit findings is a corrective action belonging to the Act phase.