Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Assessment # 1- Information Assurance and Security 1

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

It is a series of international standards developed by the International Organization for Standardization (ISO) that focus on information security management systems (ISMS) and address various aspects of information security

a)

ISO 27000 to ISO 27036

b)

ISO 27001: Information Security Management Systems - Requirements

c)

ISO 27002: Code of Practice for Information Security Controls

d)

ISO 27003: Information Security Management System Implementation Guidance

2.

This is the core standard for establishing, implementing, maintaining, and continuously improving an ISMS within an organization.

a)

ISO 27000 to ISO 27036

b)

ISO 27001: Information Security Management Systems - Requirements

c)

ISO 27002: Code of Practice for Information Security Controls

d)

ISO 27003: Information Security Management System Implementation Guidance

3.
  1. It covers various areas of information security, including organizational security, asset management, human resource security, physical and environmental security, and more.

a)

ISO 27000 to ISO 27036

b)

ISO 27001: Information Security Management Systems - Requirements

c)

ISO 27002: Code of Practice for Information Security Controls

d)

ISO 27003: Information Security Management System Implementation Guidance

4.
  1. It provides practical advice on the various phases of ISMS implementation, including planning, establishing, operating, monitoring, reviewing, maintaining, and improving the system.

a)

ISO 27000 to ISO 27036

b)

ISO 27001: Information Security Management Systems - Requirements

c)

ISO 27002: Code of Practice for Information Security Controls

d)

ISO 27003: Information Security Management System Implementation Guidance

5.

It provides guidance on defining metrics, establishing measurement processes, and reporting on the status and performance of the ISMS.

a)
  1. ISO 27004: Information Security Management - Measurement

b)

ISO 27001: Information Security Management Systems - Requirements

c)

ISO 27002: Code of Practice for Information Security Controls

d)

ISO 27003: Information Security Management System Implementation Guidance

6.
  1. It provides guidance on how to identify, assess, and treat information security risks within the context of an organization's overall risk management framework.

a)
  1. ISO 27004: Information Security Management - Measurement

b)

ISO 27005: Information Security Risk Management:

c)

ISO 27002: Code of Practice for Information Security Controls

d)

ISO 27003: Information Security Management System Implementation Guidance

7.
  1. This standard sets out the requirements for bodies providing certification of an organization's compliance with ISO 27001.

a)
  1. ISO 27004: Information Security Management - Measurement

b)

ISO 27005: Information Security Risk Management:

c)

ISO 27002: Code of Practice for Information Security Controls

d)

ISO 27006: Requirements for the Accreditation of Certification Bodies:

8.
  1. It outlines the principles and processes of auditing and provides recommendations for audit programs and the competence of auditors.

a)
  1. ISO 27007: Guidelines for Information Security Management Systems Auditing

b)

ISO 27005: Information Security Risk Management:

c)

ISO 27002: Code of Practice for Information Security Controls

d)

ISO 27006: Requirements for the Accreditation of Certification Bodies:

9.
  1. This standard offers specific guidance for cloud service providers and cloud customers on implementing information security controls within cloud computing environments.

a)
  1. ISO 27007: Guidelines for Information Security Management Systems Auditing

b)

ISO 27005: Information Security Risk Management:

c)

ISO 27017: Code of Practice for Information Security Controls for Cloud Services

d)

ISO 27006: Requirements for the Accreditation of Certification Bodies:

10.
  1. It provides guidelines for cloud service providers in handling PII and gives customers assurance about the protection of their personal data.

a)
  1. ISO 27007: Guidelines for Information Security Management Systems Auditing

b)

ISO 27018: Code of Practice for Protection of Personally Identifiable Information (PII) in Public Clouds:

c)

ISO 27017: Code of Practice for Information Security Controls for Cloud Services

d)

ISO 27006: Requirements for the Accreditation of Certification Bodies:

11.
  1. ISO 27031: Guidelines for Information and Communication Technology (ICT) Readiness for Business Continuity.

a)
  1. It covers aspects such as risk assessment, business impact analysis, development of continuity plans, and testing and exercising of ICT systems.

b)

This standard focuses on the protection of personally identifiable information (PII) within public cloud computing environments.

c)

This standard offers guidance on improving the state of cybersecurity by addressing the risks and challenges posed by cyberspace.

d)

This standard focuses on monitoring, measurement, analysis, and evaluation of the effectiveness and performance of an ISMS.

12.
  1. ISO 27032: Guidelines for Cybersecurity.

a)
  1. It covers aspects such as risk assessment, business impact analysis, development of continuity plans, and testing and exercising of ICT systems.

b)

This standard focuses on the protection of personally identifiable information (PII) within public cloud computing environments.

c)

This standard offers guidance on improving the state of cybersecurity by addressing the risks and challenges posed by cyberspace.

d)

This standard focuses on monitoring, measurement, analysis, and evaluation of the effectiveness and performance of an ISMS.

13.
  1. It is an independent, not-for-profit organization based in Europe that develops standards for information and communication technologies (ICT) including telecommunications, broadcasting, and other electronic communications networks and services.

a)

ETSI

b)

ISO 27018

c)

ISO 27031

d)

ISO 27032

14.
  1. It outlines the policies, strategies, and actions necessary to enhance cybersecurity capabilities, prevent cyber threats, and respond effectively to incidents.

a)

ETSI

b)

ISO 27018

c)

NCP

d)

ISO 27032

15.
  1. What is NIST stand for?

a)

National Institute of Standards and Technology

b)

National Instituto of Standards and Technologies

c)

National Institute of Standard and Technologies

d)

National Institute of Standards and Technologized