The PDCA Cycle Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 The PDCA Cycle flashcards as text
Which of the following best describes the relationship between PDCA and ISO/IEC 27001's Annex A controls?
Answer: Annex A controls are selected and implemented as part of Do, following risk treatment decisions made in Plan
Risk treatment in Plan identifies which Annex A controls are needed, and these are then implemented during the Do phase.
What document produced in the Plan phase specifies which risks will be treated and how?
Answer: Risk Treatment Plan
The Risk Treatment Plan documents selected risk treatment options and the controls needed for each identified risk.
In which PDCA phase would management review of the ISMS typically occur?
Answer: Check
Management review is a monitoring activity in the Check phase that evaluates the ISMS performance and suitability.
A security team patches a critical vulnerability immediately after it is discovered. Which PDCA phase does this reactive patching represent?
Answer: Act
Reacting to a discovered problem with a corrective action falls within the Act phase of the PDCA cycle.
Which of the following is an output of the 'Check' phase in an ISO 27001 ISMS?
Answer: Audit reports and nonconformity records
Audit reports and nonconformity records are typical outputs of the Check phase's monitoring and measurement activities.
Why is it important that the PDCA cycle in an ISMS is iterative rather than a one-time process?
Answer: Because the threat landscape, business context, and technology change continuously
Threats, vulnerabilities, and business requirements evolve constantly, making ongoing iteration of the PDCA cycle essential.
Which PDCA phase includes defining the ISMS scope?
Answer: Plan
Defining the ISMS scope is a foundational planning activity that determines what the ISMS will cover.