WorksheetsDay#3A: Quiz 14-15-16
Total questions: 16
Worksheet time: 8mins
What does an organization’s security architecture represent?
A set of practices used to address security requirements at a tactical level
A set of practices used to address security requirements at an operational level
A set of practices used to address security requirements at a system level
Which of the following security services aim to facilitate user identification and support shared authentication across the organization?
Boundary control
Access control
Cryptographic
What are the six cascading levels covered in the SABSA matrix for security architecture development?
Elements, purpose, procedures, personnel, area, and schedule
Functions, planning, procedures, personnel, geography, and duration
Asset, motivation, process, people, location, and time
Which of the following steps should organizations take when preparing for the implementation of information security controls, among others?
Prepare the required documented information
Conduct a cost analysis
Both A and B
Why should organizations involve employees in the process of drafting information security procedures and policies?
Because it saves time and resources during the drafting process
Because it motivates them to contribute in the implementation of the information security controls
Because it is a requirement of ISO/IEC 27001
ISO/IEC 27001 provides a specific documentation method to be used for designing and describing controls.
True
False
In how many themes are the 93 controls of Annex A grouped?
Five
Three
Four
What is the main purpose of control 6.1 Screening of Annex A of ISO/IEC 27001?
To ensure that all personnel are eligible and suitable for their roles
To ensure that employees and contractors are aware of and fulfil their information security responsibilities
To protect the organization’s interests as part of the process of any changes in employment
Who should have access to documented operating procedures for information processing facilities?
Only the top management
Only the person responsible for operating procedures
Any user that needs them
What is the main requirement of control 8.34 Protection of information systems during audit testing of Annex A?
The tester and appropriate management must appropriately manage test information
The tester and appropriate management must plan and agree on audit tests and other assurance activities involving assessment of operational systems
The tester must separate and secure the development, testing, and production environments
What is the purpose of control 5.7 Threat intelligence of Annex A?
To provide awareness of the organization’s threat environment so that the appropriate mitigation actions can be taken
To ensure appropriate flow of information
To ensure information security risks related to deliverables are effectively addressed in project management throughout the project life cycle
Among others, what must organizations do, to comply with clause 7.5.1 Documented information of ISO/IEC 27001?
Develop a procedure for the control of the documented information
Develop a guide for the control of the documented information that is accessible only by the top management
Develop a comprehensive database for the control of the documented information, storing all records in an encrypted format
In order to comply with ISO/IEC 27001, organizations should establish a complex document control system.
True
False
What does a procedure describe?
An outline of specific instructions on the steps to be taken
A detailed instruction on the use or installation, maintenance, or operation of something to an actual description of policies
A detailed explanation of the functioning of a process
What is the main purpose of the approval stage in the process of controlling and managing documents for the ISMS?
To distribute the document to all interested parties
To finalize and sign off on the documents
To identify opportunities for improvement
What are the benefits of a documented information management system?
Facilitating access to, referencing, disseminating, and archiving documents
Ensuring traceability of the documented information
Both A and B
