Ukuran huruf
Lembar kerjaISMS Short Quiz - Clause 9 - 10
Total soal: 10
Worksheet time: 6mins
What is the purpose of performance evaluation in an organization?
Assessing employee punctuality and attendance
Evaluating the speed of computer networks
Monitoring the effectiveness of cybersecurity measures
Reviewing the quality of office furniture
What is the primary purpose of an ISMS internal audit within an organization?
Ensuring compliance with external regulations and industry standards
Identifying areas for improvement and enhancing operational efficiency
Conducting background checks on potential employees
Reviewing customer feedback and satisfaction
What does "continual improvement" mean in the context of management systems?
Setting rigid standards
Halting any changes
Process for continuously enhancing system performance
Ignoring customer feedback
Ceasing new product development
What should be done if there is nonconformity in the management system?
Blame others
Identify, record, and address nonconformities
Reduce transparency
Turn a blind eye to failures
Ignore and continue business as usual
What is meant by "corrective action" in the context of nonconformities?
Blaming individuals
Ignoring issues
Actions to eliminate the causes of nonconformities
Turning a blind eye to emerging problems
Conducting external audits
What does SSDLC stand for?
Secure Software Development Language and Coding
Systematic Software Deployment and Licensing Control
Secure Software Development Life Cycle
Structured Software Design and Lifecycle Control
Secure System Deployment and Lifecycle Management
What is the primary goal of identity and access management (IAM)?
To limit access to only a few individuals
To complicate the login process for users
To manage and control user access to resources effectively
To allow unrestricted access to all users
To ignore user identities and access rights
How does the principle of least privilege relate to human resource security?
It doesn't relate, as it's a separate concept
Employees should have maximum privileges to access all information
Employees should have the least amount of privilege necessary to perform their job duties
Only senior management should have access to any information
Employees should have unrestricted access to all information
What are common threats to network security?
Software updates and patches
Strong encryption methods
Unauthorized access, malware, and phishing attacks
Regular security audits and assessments
Physical security measures
Why is protecting PII important?
To prevent identity theft
To ensure compliance with privacy regulations
To increase network speed
To encourage data sharing
To make information freely accessible to everyone
