The PDCA Cycle Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 The PDCA Cycle flashcards as text
An organization has completed its first full PDCA cycle for its ISMS. What should it do next?
Answer: Begin a new PDCA cycle incorporating lessons learned from the first cycle
PDCA is a continual cycle; after Act, the organization feeds improvements back into a new Plan phase.
Which of the following is the most accurate description of the 'Do' phase in an ISMS PDCA cycle?
Answer: Implementing and operating the controls selected during planning
The Do phase is where planned controls and processes are put into operation throughout the organization.
A financial firm applies PDCA to its ISMS after a data breach. In which phase would root cause analysis of the breach be performed?
Answer: Check
Investigating incidents and performing root cause analysis are Check phase activities that evaluate what went wrong.
Which of the following PDCA activities directly supports ISO/IEC 27001 Clause 10 (Improvement)?
Answer: Act: Taking corrective actions and pursuing continual improvement
ISO/IEC 27001 Clause 10 maps directly to the Act phase, covering nonconformity, corrective action, and continual improvement.
What is the significance of 'preventive actions' in the PDCA cycle as applied to an ISMS?
Answer: They address potential nonconformities before they occur, applied during Plan and Act phases
Preventive actions anticipate and eliminate causes of potential nonconformities, typically planned in the Plan phase and reinforced in Act.
In a PDCA cycle for ISMS, which output from the 'Act' phase becomes an input to the next 'Plan' phase?
Answer: Corrective action results and improvement proposals
The results of corrective actions and improvement decisions from Act feed directly into the next iteration of planning.
Which of the following scenarios illustrates the 'Check' phase of PDCA in an ISO 27001 ISMS?
Answer: Reviewing security metrics dashboards to assess control effectiveness
Reviewing metrics and dashboards to assess whether controls are working effectively is a core Check phase activity.