โ† All ISO 27000 Foundation Certification Flashcard Decks

The PDCA Cycle Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 The PDCA Cycle flashcards as text
  1. Which of the following best describes the relationship between PDCA and ISO/IEC 27001's Annex A controls?

    Answer: Annex A controls are selected and implemented as part of Do, following risk treatment decisions made in Plan

    Risk treatment in Plan identifies which Annex A controls are needed, and these are then implemented during the Do phase.

  2. What document produced in the Plan phase specifies which risks will be treated and how?

    Answer: Risk Treatment Plan

    The Risk Treatment Plan documents selected risk treatment options and the controls needed for each identified risk.

  3. In which PDCA phase would management review of the ISMS typically occur?

    Answer: Check

    Management review is a monitoring activity in the Check phase that evaluates the ISMS performance and suitability.

  4. A security team patches a critical vulnerability immediately after it is discovered. Which PDCA phase does this reactive patching represent?

    Answer: Act

    Reacting to a discovered problem with a corrective action falls within the Act phase of the PDCA cycle.

  5. Which of the following is an output of the 'Check' phase in an ISO 27001 ISMS?

    Answer: Audit reports and nonconformity records

    Audit reports and nonconformity records are typical outputs of the Check phase's monitoring and measurement activities.

  6. Why is it important that the PDCA cycle in an ISMS is iterative rather than a one-time process?

    Answer: Because the threat landscape, business context, and technology change continuously

    Threats, vulnerabilities, and business requirements evolve constantly, making ongoing iteration of the PDCA cycle essential.

  7. Which PDCA phase includes defining the ISMS scope?

    Answer: Plan

    Defining the ISMS scope is a foundational planning activity that determines what the ISMS will cover.