NEW
Font size
WorksheetsISO 27001:2013 AWARENESS TRAINING, 19/11/21
Total questions: 10
Worksheet time: 5mins
What are the 3 key points of aspects of information?
Conformance, Availability, Integrity
Compliance, Assessment, Integration
Confidentiality, Availability, Integrity
Confidentiality, Availability, Integration
Below are the 5 types of Information Asset, EXCEPT
People
Services
Hardcopy
Softcopy
Hardware
Which clause of ISO 27001:2013 is for Internal Audit?
Clause 6
Clause 7
Clause 8
Clause 9
Below is role in Internal Auditor, except?
Review documentation
Evaluate auditee competency
Coordinate Internal Audit at all TG Malaysia Factories (Centralized planning, schedule, memo etc.)
Interview the auditee
Why should we have documented operating procedures?
To make available to users who need to understand the process flow of their related daily tasks.
To confuse users on the process flow of related activities
Only use it when auditor checks without reading it properly
All of the above
What are the password complexity requirements when changing password?
i. Must have symbol
ii. Must have number
iii. Must have lower and upper case letter
iv. Must be at least 10 characters long
i and iii
ii and iv
i, ii, and iii
All of the above
A policy on the use of cryptographic controls for protection of information shall be _ & _
developed & implemented
implemented & improvised
improvised & implemented
All of the above
The changes to supplier services are being managed by taking into account of the criticality of business information, system and process involved, and _.
cost involved
the quality of services provided
re-assessment of risks
all of the above
IT System Contingency Plan is the measure taken for system recovery after disruption. This Contingency Plan will be activated if one the below criteria are met, except:
Incoming power outage for less than 30 minutes
System is unavailable for more than 48 hours
Facility is damaged and un-accessible for more than 24 hours
Critical systems with major impact are unavailable for more than 48 hours
How are information security event reported?
i. SMS
ii. Raise helpdesk
iii. Email
iv. Phone call
i & ii
ii, iii & iv
i, iii & iv
All of the above
