wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Day#1B - Quiz 456

Total questions: 16

Worksheet time: 8mins

Name
Class
Date
1.

Which implementation approach includes the application of best practices in project management?

a)

Business approach

b)

Iterative approach

c)

Systematic approach

2.

What is the correct definition of the term project?

a)

A unique process consisting of a set of coordinated and controlled activities to achieve an objective conforming to specific requirements

b)

The smallest identified object of work in an organization

c)

The process of planning, organizing, controlling, and reporting of a set of activities to achieve objectives

3.

Which of the following statements regarding the ISMS is correct?

a)

New technologies should be integrated when implementing the ISMS to optimize processes

b)

The roles and responsibilities of interested parties relevant to the ISMS should be defined after the implementation process

c)

The ISMS should be integrated into existing processes of the organization

4.

Which of the following is NOT a factor that determines the approach for implementing an ISMS?

a)

Maturity level of controls and processes

b)

Applicable laws and regulations

c)

Dependence on technology

5.

What is the iterative approach?

a)

Overall implementation of the ISMS processes, not by isolating certain processes

b)

Rapid implementation of the ISMS by adhering to the minimum requirements of the standard and proceeding with continual improvement thereafter

c)

Harmonization of the ISMS with other management systems established within the organization

6.

Why is it important to understand the mission, objectives, values, and strategies of an organization?

a)

To facilitate the internal audit process

b)

To create a map of all the processes

c)

To ensure consistent alignment with information security goals

7.

What does ISO/IEC 27001 require for establishing information security objectives, among others?

a)

To involve all stakeholders

b)

To retain documented information

c)

To evaluate their achievement quarterly

8.

______________________________________ is a person or an organization that can affect, be affected by, or perceive itself to be affected by a decision or activity.

a)

A customer

b)

An interested party

c)

Provider

9.

Which of the following is NOT an element that should be considered when analyzing the organization’s internal context?

a)

Competitors

b)

Governance and organizational structure

c)

Information flows and decision-making processes

10.

Which of the following requirements of interested parties must organizations consider, according to clause 4.2 of ISO/IEC 27001?

a)

Legal and regulatory requirements

b)

Climate change requirements

c)

Both A and B

11.

What factors can affect the ISMS scope, among others?

a)

Support functions, such as IT services and software applications

b)

The outsourced functions

c)

Both A and B

12.

When determining the ISMS scope, the organization must consider interfaces and dependencies between the activities it performs and those performed by other organizations.

a)

True

b)

False

13.

Which of the following dimensions should be considered when defining the boundaries of the ISMS scope?

a)

Information system boundaries

b)

Physical boundaries

c)

Both A and B

14.

Which ISMS boundaries can organization determine by evaluating the responsibilities of decision-makers and their areas of influence?

a)

Organizational

b)

Physical

c)

Information system

15.

Which of the following statements regarding the ISMS scope is correct?

a)

The ISMS scope should be classified as confidential information

b)

The ISMS scope does not have to consider the needs and expectations of interested parties

c)

The ISMS scope should be available as documented information

16.

What is the recommended process for making changes in ISMS scope?

a)

Changes must be automatically implemented if the organization is certified by a conformity assessment body (CAB)

b)

Changes should be justified and approved during a management review

c)

Changes should be documented and be approved only by the ISMS project manager