WorksheetsDay#2A;Quiz LI Multimatics
Total questions: 15
Worksheet time: 8mins
According to ISO/IEC 27001, who is responsible for establishing the information security policy?
The top management
The ISMS project manager
The information security manager
What is the difference between a policy and a guideline?
A policy states the intentions and direction of an organization, whereas a guideline states how something should be done
A policy is a type of a guideline that provides guidance for different topics
A policy is a document stating how something should be done, whereas a guideline is an explanation of procedures
Which type of policies specifies the internal requirements of another policy and covers a particular target audience?
High-level general policies
High-level specific policies
Topic-specific policies
Which of the following is a high-level specific policy?
Incident management policy
Information security policy
Policy on cryptography
What is the first phase of the information security policy development life cycle?
Policy construction
Policy monitoring and maintenance
Risk assessment
What does ISO/IEC 27005 provide?
Requirements for information security risk management
Guidelines for managing any type of risk, regardless of its nature or consequences
Guidelines for information security risk management
What should be considered when selecting a risk assessment methodology when implementing an ISMS, among others?
The scalability of the methodology to integrate various project sizes and complexities
Compatibility of the methodology with all the criteria of ISO/IEC 27001
Residual risks documented in the risk treatment plan
Which of the following best defines primary/business assets in the context of an organization’s information security?
Primary/business assets include physical infrastructure like buildings and warehouse
Primary/business assets are components of the information system that support other asset
Primary/business assets refer to information or processes of value for an organization
Which phase of risk assessment aims to find, recognize, and describe risks?
Risk identification
Risk evaluation
Risk analysis
Which of the following processes involves comparing the results of the risk analysis with the risk criteria to determine whether the risk and its magnitude is acceptable or tolerable?
Risk treatment
Risk evaluation
Risk acceptance
Which process modifies risk?
Risk evaluation
Risk identification
Risk treatment
Which of the following factors that may influence risks should organizations continually monitor, among others?
New sources of risk
Changes is laws and regulations
Both A and B
According to ISO/IEC 27001, what must the Statement of Applicability contain?
The timeframes for auditing the controls
The justification for excluding any of the Annex A controls
The names of individuals responsible for the effectiveness of the controls
How does an organization select the security controls of ISO/IEC 27001, Annex A?
Based on the risk assessment results
Based on the top management’s decision
Based on the internal audit report
Which of the following is a common reason for excluding controls of Annex A of ISO/IEC 27001?
Streamline of the organization’s operational processes and complexity reduction
Violation of legal, statutory, or contractual requirements
Potential conflicts with industry best practices and guidelines
