wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ISMS Revision

Total questions: 22

Worksheet time: 12mins

Name
Class
Date
1.

ISO/IEC 27001:2013 covers which of the following;

a)

Information technology. Security techniques. Information security management systems.

b)

Information technology. Security techniques. Code of practice for information security

c)

Information technology. Security techniques. Information security

2.

ISO/IEC 27001:2013 essentially covers ;

a)

Requirements

b)

Controls

c)

Risk management

3.

Which of the following is a form of Information (select more than one)

a)

printed or written on paper

b)

Stored electronically

c)

web publications

d)

phone calls

4.

What does the CIA Triad represent

a)

Confidentiality, integrity and availability

b)

Confidentiality, integrity and authentication

c)

Creditability, integrity and access

d)

Constance, informative and availability

5.

In addition to CIA , Authentication is often another security goal. Which of the following is a good definition of Authentication?

a)

Validated the data is in the correct format

b)

Ensuring data remains unchanged

c)

Ensuring the data is genuine

d)

Ensuring the data is accessible when requested

6.

ISO 27002 contains are comprehensive set of best practices on

a)

Organisation assets

b)

Audit processes

c)

Risk assessments

d)

information security controls

7.

Which of these describes 'out-of-scope' ;

a)

Elements that your organisation has decided to ignore during audit - due to some constraints , even though they contact assets.

b)

Elements that your organisation either has no control over (such as third-party products) or that don’t give access to sensitive information.

c)

Elements that your organisation didn't consider until after audit.

8.

What is one benefit of ISO27001 compliance?

a)

Guarantees the IT Security system is safe

b)

Ensures all staff and third parties knows their data is shared correctly

c)

Provides a defined framework that organises information security management, governance and operational security activities.

d)

Defines the specific technical security measures a company must take.

9.

Which of the following must the organisation produce?

a)

Statement of control

b)

Statement of applicability

c)

Statement of implementation

10.

What is one advantage of ISO 27001 certification ?

a)

Higher Management are responsible.

b)

Over Confidence in your defences

c)

Review process is guaranteed

d)

IT risks and potential damage are mitigated.

11.

Within ISO standards, what does “shall” indicate?

a)

A permission

b)

A recommendation

c)

A requirement

d)

A capability

12.

Ideally how often should an organisation perform an information security risk assessments?

a)

At planned intervals or when significant changes are proposed to occur

b)

Every six months or when significant changes are proposed to occur

c)

Every 12 months, or when significant changes are proposed to occur

13.

Who establishes the information security policy?

a)

The employees

b)

Internal Auditor

c)

The Quality Manager

d)

Top Management

14.

PDCA stand for?

a)

Prepare, Do, Combine, Act

b)

Plan, Design, Confirm, Act

c)

Plan, Do, Check, Act

15.

What does NIST stand for?

a)

Network Institute and Standards of Technology

b)

National Institute of Security and Technology

c)

National Institute of Standards and Technology

d)

National Information Security Techniques

16.

The purpose of NIST SP 800-50 is to build an Information

Technology Security Awareness and Training Program" which focuses on information security awareness programs

a)

True

b)

False

17.

ISO 27005 is asset driven.

a)

True

b)

False

18.

NIST is threat driven.

a)

True

b)

False

19.

Risk Assessment Tiers in SP 800-30

At Tier 1 organizations use risk assessments to;

a)

systemically evaluate risks associated with organizational governance and management activities.

b)

systemically evaluate risks associated with mission/business processes.

c)

effectively support the implementation of the Risk Management Framework.

20.

Risk Assessment Tiers in SP 800-30

At Tier 2 organizations use risk assessments to ;

a)

systemically evaluate risks associated with organizational governance and management activities.

b)

systemically evaluate risks associated with mission/business processes.

c)

effectively support the implementation of the Risk Management Framework.

21.

Risk Assessment Tiers in SP 800-30

At Tier 3 organizations use risk assessments to ;

a)

systemically evaluate risks associated with organizational governance and management activities.

b)

systemically evaluate risks associated with mission/business processes.

c)

effectively support the implementation of the Risk Management Framework.

22.

HAZOP (HAZard and OPerability) study is an analysis of how ________ from the design specifications in a system can arise and whether they can result in hazards

a)

threats

b)

deviations

c)

missed assets