WorksheetsDay#1B - Quiz 456
Total questions: 16
Worksheet time: 8mins
Which implementation approach includes the application of best practices in project management?
Business approach
Iterative approach
Systematic approach
What is the correct definition of the term project?
A unique process consisting of a set of coordinated and controlled activities to achieve an objective conforming to specific requirements
The smallest identified object of work in an organization
The process of planning, organizing, controlling, and reporting of a set of activities to achieve objectives
Which of the following statements regarding the ISMS is correct?
New technologies should be integrated when implementing the ISMS to optimize processes
The roles and responsibilities of interested parties relevant to the ISMS should be defined after the implementation process
The ISMS should be integrated into existing processes of the organization
Which of the following is NOT a factor that determines the approach for implementing an ISMS?
Maturity level of controls and processes
Applicable laws and regulations
Dependence on technology
What is the iterative approach?
Overall implementation of the ISMS processes, not by isolating certain processes
Rapid implementation of the ISMS by adhering to the minimum requirements of the standard and proceeding with continual improvement thereafter
Harmonization of the ISMS with other management systems established within the organization
Why is it important to understand the mission, objectives, values, and strategies of an organization?
To facilitate the internal audit process
To create a map of all the processes
To ensure consistent alignment with information security goals
What does ISO/IEC 27001 require for establishing information security objectives, among others?
To involve all stakeholders
To retain documented information
To evaluate their achievement quarterly
______________________________________ is a person or an organization that can affect, be affected by, or perceive itself to be affected by a decision or activity.
A customer
An interested party
Provider
Which of the following is NOT an element that should be considered when analyzing the organization’s internal context?
Competitors
Governance and organizational structure
Information flows and decision-making processes
Which of the following requirements of interested parties must organizations consider, according to clause 4.2 of ISO/IEC 27001?
Legal and regulatory requirements
Climate change requirements
Both A and B
What factors can affect the ISMS scope, among others?
Support functions, such as IT services and software applications
The outsourced functions
Both A and B
When determining the ISMS scope, the organization must consider interfaces and dependencies between the activities it performs and those performed by other organizations.
True
False
Which of the following dimensions should be considered when defining the boundaries of the ISMS scope?
Information system boundaries
Physical boundaries
Both A and B
Which ISMS boundaries can organization determine by evaluating the responsibilities of decision-makers and their areas of influence?
Organizational
Physical
Information system
Which of the following statements regarding the ISMS scope is correct?
The ISMS scope should be classified as confidential information
The ISMS scope does not have to consider the needs and expectations of interested parties
The ISMS scope should be available as documented information
What is the recommended process for making changes in ISMS scope?
Changes must be automatically implemented if the organization is certified by a conformity assessment body (CAB)
Changes should be justified and approved during a management review
Changes should be documented and be approved only by the ISMS project manager
