Font size
WorksheetsISO 27001:2013 Awareness
Total questions: 20
Worksheet time: 11mins
Which standard are we implementing now?
ISO 9001:2015
ISO 22301: 2013
ISO/IEC 27001:2013
ISO 31000
Below are the benefits of implementing ISO/IEC 27001:2013 except...
Identify and improve current security processes
The exposure to risk is maximized
Ensures compliance with client, regulatory, and legal requirements
Reduce the costs and risks of security breaches
Choose all which is related to cyber-security threats only.
(More than one answer)
Ransomware
Freeware
Spyware
Malware
DDoS
Based on the picture, which policy are we looking at?
HR Policy
Workspace Management Policy
Clean Desk Policy
Clean Table Policy
Which is an example of a strong password?
papayousini
123456789
Z%S5jh~D
abc1234
"Information Security is everyone's responsibility"
True or False?
True
False
"Passwords should be saved in your device so it is easier for you to remember them"
True or False?
True
False
What would you do if received a suspicious email or ads claiming you've won a prize?
Click and claim the prize!
I will ignore it. It highly contains malware
What is the purpose of Integrity?
The information is safe
from accidental or
intentional modification
or alteration
The information is safe
from accidental or
intentional disclosure
The information is
available to authorized
users when needed
Who should practice the Clean Desk policy in the office?
All the managers
Everyone
Finance Department
ISMS Department
ISO 27001 was developed to "provide a model for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an information security management system.
True
False
Which of the below are current threats to many organizations?
Fraud
Loss of information
Unauthorized access
All of the above
Information security objectives shall be;
Consistent with the information security policy
Measurable (if practicable)
Communicated
All of the above
"ISO 27001:2013 is focused solely on the protection of personal information"
Is the above statement 'true' or 'false'?
True
False
What does the C in the CIA of Information Security stand for?
Confidentiality
Context
Conformity
How is ‘Information Security’ defined in an ISMS (Information Security Management System)?
Maintenance of security services
Preservation of confidentiality, integrity, and availability of information
Protection of data and information
ISMS is an abbreviation for...
Internet Security Management System
Incident Security Management System
Information Security Management System
Information security policies
What are the key principles of Information Security?
Accessibility, Continuity & Informative
Availability, Confidentiality & Integrity
Answerable, Continuity & Integrity
Achievable, Continuous & Informative
What is Information Security Policy?
A set of processes to ensure data assets are formally managed
A formal business contingency & disaster recovery plan
A guideline for Internet Security
Provides a definitive statement of information security policy
What is the best way to ensure the effectiveness of antivirus software?
Run the antivirus software at least every hour
Test the software by infecting your machine with a virus
Install the latest version & update security patches
Use the outdated antivirus software
