Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Activity 2 - ISMS

Total questions: 10

Worksheet time: 5mins

Name
Class
Date
1.

What is the main focus of ISO 27001?

a)

Financial risk management

b)

Information security management

c)

Environmental management

d)

Quality management

2.

Which of the following standards is focused on information security risk management?

a)

ISO 27001

b)

ISO 27003

c)

ISO 27005

d)

ISO 27004

3.

What is ISO 27003 primarily concerned with?

a)

Information security risk assessment methodology

b)

Guidance on implementing an Information Security Management System (ISMS)

c)

Security controls for data protection

d)

Metrics and reporting of ISMS effectiveness

4.

Which of the following is a concept introduced in ISO 27001:2022 related to leadership?

a)

The requirement for a full-time Chief Information Security Officer (CISO)

b)

A stronger emphasis on the involvement of top management in the ISMS

c)

Introduction of a dedicated security department

d)

Mandating employee cybersecurity awareness training

5.

What does ISO 27004 focus on?

a)

Information security management framework

b)

Guidance on security control testing

c)

Monitoring and measurement of the ISMS

d)

Implementation of cryptographic controls

6.

What is the purpose of conducting a risk assessment?

a)

To identify, evaluate, and treat information security risks

b)

To monitor the effectiveness of security policies

c)

To measure the financial impact of security incidents

d)

To define the organizational structure for information security

7.

Which of the following is the main objective of an Information Security Management System (ISMS)?

a)

To create backup systems for information storage

b)

To safeguard personal data from unauthorized access

c)

To ensure ongoing confidentiality, integrity, and availability of data

d)

To ensure compliance with local regulations only

8.

What does the "Do" phase in the PDCA cycle involve?

a)

Reviewing the effectiveness of security controls

b)

Establishing the information security objectives

c)

Implementing the ISMS policies and controls

d)

Conducting internal and external audits

9.

What new controls are added in ISO27001:2022 version?

a)

Cloud Security, Business Continuity, Physical security of hardware

b)

Web Filtering, Threat Intelligence, Data Leakage Prevention

c)

Access Control, Web Filtering, BCP Drill

d)

Outsource Development, BYOD, Threat Intelligence

10.

What is the key focus of the control "Information System Acquisition, Development, and Maintenance"?

a)

Ensuring systems are developed in compliance with ISO 27001 standards

b)

Managing risks associated with the acquisition and ongoing development of information systems

c)

Enforcing continuous monitoring of system vulnerabilities

d)

Ensuring that all software used by an organization is open-source