wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

ISO 27001:2013 AWARENESS TRAINING, 19/11/21

Total questions: 10

Worksheet time: 5mins

Name
Class
Date
1.

What are the 3 key points of aspects of information?

a)

Conformance, Availability, Integrity

b)

Compliance, Assessment, Integration

c)

Confidentiality, Availability, Integrity

d)

Confidentiality, Availability, Integration

2.

Below are the 5 types of Information Asset, EXCEPT

a)

People

b)

Services

c)

Hardcopy

d)

Softcopy

e)

Hardware

3.

Which clause of ISO 27001:2013 is for Internal Audit?

a)

Clause 6

b)

Clause 7

c)

Clause 8

d)

Clause 9

4.

Below is role in Internal Auditor, except?

a)

Review documentation

b)

Evaluate auditee competency

c)

Coordinate Internal Audit at all TG Malaysia Factories (Centralized planning, schedule, memo etc.)

d)

Interview the auditee

5.

Why should we have documented operating procedures?

a)

To make available to users who need to understand the process flow of their related daily tasks.

b)

To confuse users on the process flow of related activities

c)

Only use it when auditor checks without reading it properly

d)

All of the above

6.

What are the password complexity requirements when changing password?

i. Must have symbol

ii. Must have number

iii. Must have lower and upper case letter

iv. Must be at least 10 characters long

a)

i and iii

b)

ii and iv

c)

i, ii, and iii

d)

All of the above

7.

A policy on the use of cryptographic controls for protection of information shall be _ & _

a)

developed & implemented

b)

implemented & improvised

c)

improvised & implemented

d)

All of the above

8.

The changes to supplier services are being managed by taking into account of the criticality of business information, system and process involved, and _.

a)

cost involved

b)

the quality of services provided

c)

re-assessment of risks

d)

all of the above

9.

IT System Contingency Plan is the measure taken for system recovery after disruption. This Contingency Plan will be activated if one the below criteria are met, except:

a)

Incoming power outage for less than 30 minutes

b)

System is unavailable for more than 48 hours

c)

Facility is damaged and un-accessible for more than 24 hours

d)

Critical systems with major impact are unavailable for more than 48 hours

10.

How are information security event reported?

i. SMS

ii. Raise helpdesk

iii. Email

iv. Phone call

a)

i & ii

b)

ii, iii & iv

c)

i, iii & iv

d)

All of the above