WorksheetsCertiprof ISO27001 Foundation - Exercise
Total questions: 40
Worksheet time: 20mins
According to ISO IEC 27001:2022 Clause 4.3, external and internal issues, interfaces and
dependencies must be considered to define the ISMS scope.
This statement is:
True
False
According to ISO IEC 27001:2022, the information security risk assessment process requires
identifying risk owners and establishing and maintaining information security risk criteria.
This statement is:
True
False
Which statement describes the benefits of an information security management system?
An aid to management in structuring its approach to information security management.
Enables organizations to properly manage disruptive incidents.
Allows the organization to focus on containing the impact caused by information security incidents.
An aid in the identification of nonconformities during audits.
Appointing at least two internal auditors for the information security system is described as a
critical success factor of an information security management system (ISMS). This statement is:
Trus
False
Implementing an effective information security awareness, training, and education program is
described as a critical success factor of an information security management system (ISMS).
This statement is:
True
False
ISO IEC 27001:2022 requires information security objectives to be part of:
Internal audits.
ISMS reviews.
The information security policy.
The SoA.
According to ISO IEC 27001:2022 in its clause 9.3 Management review, communicating the
importance of complying with the requirements of the ISMS is a top management responsibility
concerning the ISMS:
True
False
According to ISO IEC 27001:2022 in clause 5.1 Leadership and Commitment, how should top
management provide evidence of their commitment to the ISMS?
A) Promoting continuous improvement.
B) Directing and supporting people to contribute to the effectiveness of the information security
management system.
A & B are correct.
None is requested by clause 5.1.
According to ISO IEC 27001:2022 in clause 9.3, the objective of the top management review of
the ISMS is to ensure its suitability, adequacy, and continuing effectiveness.
True
False
According to ISO IEC 27001:2022 the SoA must contain:
1. Evidence of senior management authorization of controls.
2. A list of the risks applicable to the organization.
3. The necessary controls with their justifications for inclusion and exclusion.
4. The information security policy.
(A) Only 3.
(B) 2 and 4.
(C) Only 1.
(D) All of correct
According to ISO IEC 27001:2022 a Statement of Applicability should include a justification for
exclusion and inclusion of controls considered necessary.
True
False
According to ISO IEC 27001:2022 the interfaces and dependencies between the activities
performed by the organization and those performed by other organizations must be considered in
determining the scope of the information security management system. This statement is:
True
False
According to ISO IEC 27001:2022, supporting the drive for continuous improvement is
considered a responsibility of the IT manager in the organization. This statement is:
True
False
Which of the following does not correspond to the phases of the PDCA cycle?
1. Plan
2. Do.
3. Assure.
4. Act.
(A): 1
(B): 2
(C): 3
(D): 4
According to ISO IEC 27001:2022 clause 7.4 Communication, the activity within the ISMS of
communicating the importance of effective information security management and compliance with the
requirements of the ISMS is a responsibility of the IT manager.
(A): False.
(B): True.
True
False
According to ISO IEC 27001:2022 Clause 5.2, the information security policy should:
(A): Be available as documented information.
(B): Be communicated within the organization.
(C): Be available to interested parties, as appropriate.
(D): All of the above.
According to ISO IEC 27001:2022, regarding risk management, the organization shall:
(A): Define and implement an information security risk assessment process.
(B): Define and implement an information security risk treatment process.
(C): Maintain documented information on information security risk assessment and risk treatment
processes.
(D): All of the above.
According to ISO IEC 27001:2022, regarding clause 7.5 documented information, the
organization shall ensure:
1. That it is available and ready for use, where and when needed.
2. That it is adequately protected (e.g., against loss of confidentiality, misuse, or loss of integrity).
3. To perform activities as applicable to ensure the preservation of legibility.
(A): Only 1 is valid
(B): 1 and 3 are valid.
(C): None since clause 7.5 does not refer to documented information of an ISMS.
(D): All are valid.
According to ISO IEC 27001:2022, regarding clause 9.1 Monitoring, Measurement, Analysis
and Evaluation, the organization shall define:
1. What needs to be tracked and measured, including information security processes and controls.
2. The methods of monitoring, measurement, analysis, and evaluation, as applicable, to ensure valid results.
(A): Only 1 is valid.
(B): Only 2 is valid.
(C): None since clause 9.1 does not refer to the Monitoring, Measurement, Analysis, and Evaluation of an
ISMS.
(D): All are valid.
According to ISO IEC 27001:2022, regarding clause 9.1 Internal audits, the organization shall:
1. Plan, establish, implement and maintain an audit program(s) that includes frequency, methods,
responsibilities, planning requirements, and reporting.
2. Audit programs should consider the importance of the processes involved and the results of previous
audits.
3. Conduct internal audits at planned intervals, to provide information about the information security
management system.
(A): Only 1 is valid.
(B): Only 2 is valid.
(C): None since clause 9.1 does not refer to internal audits.
(D): All are valid.
ISO/IEC 27002:2022 provides mandatory requirements for a risk management approach, while
ISO/IEC 27001:2022 contains mandatory requirements for an ISMS. This statement is:
True
False
ISO/IEC 27001:2022 contains mandatory requirements, while ISO/IEC 27002:2022 provides
guidance on information security controls. This statement is:
True
False
According to ISO IEC 27001:2022, regarding clause 8.3 Treatment of Information Security
Risks, the organization shall:
1. Implement the information security risk management plan.
2. Retain documented information on the results of the treatment of information security risks.
(A): Only 1 is valid.
(B): Only 2 is valid.
(C): None, since clause 8.3 does not refer to the Information Security risk treatment plan.
(D): All are valid.
According to ISO/IEC 27001:2022 in its clause 9.3, The internal audit team is required to
review the ISMS to ensure its suitability, adequacy and effectiveness. This statement is:
True
False
According to ISO/IEC 27001:2022, the organization shall establish, maintain and continually
improve an information security management system. This statement is:
True
False
According to ISO/IEC 27001:2022 regarding clause 7.5 Documented Information, the
organization shall ensure, as appropriate:
1. Identification and description (e.g., title, date, author or reference number).
2. Format (e.g., language, software version, graphics) and its media (e.g., paper, electronic).
3 The review and approval regarding suitability and adequacy.
(A): Only 1 is valid.
(B): Only 2 is valid.
(C): None since clause 7.5 does not refer to the treatment of documented information of an ISMS.
(D): All are valid.
ISO/IEC 27001:2022 regarding clause 6.1 actions to address risks and opportunities, states
that mitigate, assume, share and eliminate are:
(A): Risk treatment options.
(B): The classification of controls in Appendix A.
(C): Risk classification for the SOA.
(D): All are valid.
Durability, Integrity and Confidentiality are the three main aspects of information security. This
statement is:
True
False
In ISO IEC 27001:2022, which clause states that the organization shall conduct internal audits
at planned intervals, to provide information about the information security management system:
(A): Clause 9.1
(D): None of the above.
(C): Clause 9.3
(B): Clause 9.2
In ISO IEC 27001:2022, which clause states that the organization shall determine the
necessary competence of persons who perform, under its control, work that affects its information
security performance:
(A): Clause 7.1
(B): Clause 7.2
(C): Clause 7.3
(D): Clause 7.4
In ISO IEC 27001:2022, which clause states that the organization must identify the risks
associated with the loss of confidentiality, integrity and availability of information:
(A): Clause 6.1
(B): Clause 6.2
(C): Clause 6.3
(D): Clause 6.4
In ISO IEC 27001:2022, the definition of _________________ is the property that an entity is
what it claims to be.
(A): Authenticity.
(B): Verification.
(C): Authorization.
(D): Validation.
In ISO IEC 27001:2022, ____________________ is defined as a systematic, independent and
documented process for obtaining audit evidence and evaluating it objectively to determine the extent to
which audit criteria are met.
(A): Audit.
(B): Senior Management Review.
(C): Information security policy.
(D): ISO IEC 27001:2022 Standard.
The _____________________ standard has been designed to "provide requirements for
establishing, implementing, maintaining and continually improving an information security management
system".
(A): 31000:2018
(B): 19011:2018
(C): 27002:2022
(D): 27001:2022
In ISO IEC 27001:2022 in clause 4.3, during the determination of the Scope of the Information
Security Management System the _________ and the ____________ should be considered.
(A): The external and internal dependencies mentioned in section 4.1 and the risks mentioned in section
4.2.
(B): Stakeholders and risks surrounding the organization.
(C): Stakeholders and requirements.
.
(D): The external and internal issues mentioned in section 4.1 and the requirements mentioned in section
4.2
According to ISO IEC 27001:2022, ________________ is defined as the risk remaining after risk
treatment.
(A): Secondary risk.
(B): Security incident.
(C): Vulnerability.
(D): Residual Risk
According to ISO IEC 27001:2022, ________________ during its ________________ should include
considerations on:
Changes in external and internal issues that are relevant to the ISMS.
The status of actions since previous management reviews.
Opportunities for continuous improvement.
(A): Senior Management during its internal audit.
(B): Auditors during their internal audit.
(C): Top Management during its ISMS review.
(D): Auditors during their ISMS review.
In ISO IEC 27001:2022, which clause states that the organization shall determine the need for
internal and external communications relevant to the information security management system.
(A): Clause 7.1
(B): Clause 7.2
(C): Clause 7.3
(D): Clause 7.4
In ISO IEC 27001:2022, which clause states that people working under the control of the
organization should be aware of the information security policy.
(A): Clause 7.1
(B): Clause 7.2
(C): Clause 7.3
(D): Clause 7.4
In ISO IEC 27001:2022, which clause states that when a nonconformity occurs, the
organization shall react to the nonconformity, and deal with the consequences.
(A): Clause 10.1
(B): Clause 10.2
(C): Clause 9.2
(D): Clause 9.3
