Font size
WorksheetsISMS Revision
Total questions: 22
Worksheet time: 12mins
ISO/IEC 27001:2013 covers which of the following;
Information technology. Security techniques. Information security management systems.
Information technology. Security techniques. Code of practice for information security
Information technology. Security techniques. Information security
ISO/IEC 27001:2013 essentially covers ;
Requirements
Controls
Risk management
Which of the following is a form of Information (select more than one)
printed or written on paper
Stored electronically
web publications
phone calls
What does the CIA Triad represent
Confidentiality, integrity and availability
Confidentiality, integrity and authentication
Creditability, integrity and access
Constance, informative and availability
In addition to CIA , Authentication is often another security goal. Which of the following is a good definition of Authentication?
Validated the data is in the correct format
Ensuring data remains unchanged
Ensuring the data is genuine
Ensuring the data is accessible when requested
ISO 27002 contains are comprehensive set of best practices on
Organisation assets
Audit processes
Risk assessments
information security controls
Which of these describes 'out-of-scope' ;
Elements that your organisation has decided to ignore during audit - due to some constraints , even though they contact assets.
Elements that your organisation either has no control over (such as third-party products) or that don’t give access to sensitive information.
Elements that your organisation didn't consider until after audit.
What is one benefit of ISO27001 compliance?
Guarantees the IT Security system is safe
Ensures all staff and third parties knows their data is shared correctly
Provides a defined framework that organises information security management, governance and operational security activities.
Defines the specific technical security measures a company must take.
Which of the following must the organisation produce?
Statement of control
Statement of applicability
Statement of implementation
What is one advantage of ISO 27001 certification ?
Higher Management are responsible.
Over Confidence in your defences
Review process is guaranteed
IT risks and potential damage are mitigated.
Within ISO standards, what does “shall” indicate?
A permission
A recommendation
A requirement
A capability
Ideally how often should an organisation perform an information security risk assessments?
At planned intervals or when significant changes are proposed to occur
Every six months or when significant changes are proposed to occur
Every 12 months, or when significant changes are proposed to occur
Who establishes the information security policy?
The employees
Internal Auditor
The Quality Manager
Top Management
PDCA stand for?
Prepare, Do, Combine, Act
Plan, Design, Confirm, Act
Plan, Do, Check, Act
What does NIST stand for?
Network Institute and Standards of Technology
National Institute of Security and Technology
National Institute of Standards and Technology
National Information Security Techniques
The purpose of NIST SP 800-50 is to build an Information
Technology Security Awareness and Training Program" which focuses on information security awareness programs
True
False
ISO 27005 is asset driven.
True
False
NIST is threat driven.
True
False
Risk Assessment Tiers in SP 800-30
At Tier 1 organizations use risk assessments to;
systemically evaluate risks associated with organizational governance and management activities.
systemically evaluate risks associated with mission/business processes.
effectively support the implementation of the Risk Management Framework.
Risk Assessment Tiers in SP 800-30
At Tier 2 organizations use risk assessments to ;
systemically evaluate risks associated with organizational governance and management activities.
systemically evaluate risks associated with mission/business processes.
effectively support the implementation of the Risk Management Framework.
Risk Assessment Tiers in SP 800-30
At Tier 3 organizations use risk assessments to ;
systemically evaluate risks associated with organizational governance and management activities.
systemically evaluate risks associated with mission/business processes.
effectively support the implementation of the Risk Management Framework.
HAZOP (HAZard and OPerability) study is an analysis of how ________ from the design specifications in a system can arise and whether they can result in hazards
threats
deviations
missed assets
