wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ISO 27001 Lead Implementer

Total questions: 40

Worksheet time: 23mins

Name
Class
Date
1.

Which activity summarizes the ACT phase of the PDCA in an information security management system?

a)

Monitor the ISMS.

b)

Review the entire ISMS and issue findings.

c)

Continuous improvement.

d)

Internal Audit and issue findings.

2.

To comply with the requirement of ISO/EC 27001:2022 we must establish a program of internal audits that allow us to review the ISMS. What is the purpose of an audit program?

a)

Obtain objective evidence and evaluate it objectively to determine the extent to which the audit criteria are met.

b)

Ensure that all controls are aligned to the standard and check that the ISMS we have implemented complies with the wishes of top management.

c)

Provide information on whether the ISMS meets the organization's own requirements for its ISMS as well as those of ISO/IEC 27001:2022.

d)

An audit program defines the structure and responsibilities for planning, conducting, reporting and monitoring on individual audit activities. As such, it should ensure that the audits performed have the appropriate scope, minimize the impact on the organization's operations and maintain the required quality of the audits.

3.

It is a set and structure of elements that describe the level of maturity of an entity in a given aspect, each model proposes a scale of maturity or compliance of 4, 5 or 6 levels:

a)

Senior Management Reviews.

b)

Internal Audits.

c)

Maturity Model.

d)

Risk Analysis.

4.

What is PESTEL analysis used for in the context of ISO/IEC 27001:2022?

a)

PESTEL analysis is a framework for analyzing the key factors (political, economic, sociological, technological, legal and environmental) that have an external influence on an organization.

b)

The PESTEL analysis is used to determine the internal aspect of the company and help define the scope of the management system.

5.

Executing processes, collecting records and evaluating the consequences on planned and unplanned changes as a result of the planning phase, to which stage of the PDCA cycle do they belong?

a)

Act.

b)

Do.

c)

Plan.

d)

Check.

6.

What is the purpose of incident management using control 5.26?

a)

Information security incidents shall be responded to in accordance with documented procedures.

b)

Always ensure that information security incident management is implemented given its global importance.

c)

Comply with the requirements of ISO/IEC 27002.

d)

Comply with the information security policy.

7.

You are working as a lead implementer of ISO/IEC 27001:2022. You recommend evaluating the update of the current Statement of Applicability (SoA). Why is this update recommendation being made?

a)

Because it is updated after each event.

b)

Because the standard requires an update every 3 months.

c)

Because risks are not eliminated.

d)

Because risks are constantly evaluated and updated.

8.

You have been consulted by a team working on the implementation of an ISMS. What document is produced after conducting a GAP analysis?

a)

Action plan.

b)

Audit checklist.

c)

Statement of applicability.

d)

Business case.

9.

You are working as a lead implementer of ISO/IEC 27001:2022 in the role of an external consultant. Which of the following are requirements and conditions for defining the scope of the information security management system (ISMS)?

a)

The scope must consider the organization’s context, interested parties, interfaces, and dependencies.

b)

The scope should only include IT systems and exclude business processes.

c)

The scope can be defined arbitrarily without considering external requirements.

d)

The scope must be limited to a single department regardless of risk.

10.

As the lead implementer of ISO/IEC 27001:2022, you recommend establishing a hierarchy of policies for the definition of information security policies. What are the levels you would recommend following?

a)

High level, IS policy, specific policies.

b)

Management and operational policies.

c)

A combination of A and B.

d)

None of the above.

11.

What is the purpose of controlling the transfer of information using control 5.14?

a)

Always ensure that the control is implemented given its global importance in the transfer of information that occurs naturally today.

b)

The only valid purpose for implementing this control is to avoid non-compliance with legal obligations such as the personal data protection law.

c)

Comply with the requirements of ISO/IEC 27002.

d)

Establish information transfer rules, procedures or agreements for all types of transfer facilities within the organization and between the organization and other parties.

12.

As lead implementer of ISO/IEC 27001:2022 you are supporting the definition of the information security policy. Some aspects to keep in mind are:

a)

Understanding stakeholder needs and expectations.

b)

Only internal needs because it is a business management system.

c)

Only external needs because the aim is to protect customer and user information.

d)

None of the above.

13.

Control 5.9, Inventory of information and other associated assets, is considered:

a)

Inventory.

b)

Owners of the assets.

c)

Information transfer.

14.

What is the categorization of Annex A in ISO IEC 27001:2022?

a)

Annex A divides the 93 controls into 4 themes: Political, Financial, Cultural and Legal.

b)

Annex A divides the 93 controls into 4 themes: Organizational, People, Physical and Technological.

c)

Annex A divides the 93 controls into 4 themes: Organizational, Human, Physical and Technological.

d)

Annex A continues with the same structure of its predecessor ISO IEC 27001:2013.

15.

The ISO/EC 27001:2022 standard establishes as a requirement, the need to define an Information Security Policy appropriate to the needs of the organization. Select the best answer that complements this definition.

a)

Describes the strategic importance of the information security management system for the organization and shall be available as documented information.

b)

It is a document that establishes in writing the "when" and "how" an organization plans to protect its information and information assets. The Information Security Policy is a living document, so it should be reviewed every six months to ensure that it is adequate to the needs.

c)

Establishes the implementation and monitoring guide of the ISMS. The Information Security Policy must be protected to prevent all company employees from knowing about it.

d)

A document that establishes in writing the "why" and "when" an organization plans to protect its information and information assets.

16.

As a lead ISMS implementer you must establish a risk assessment and risk treatment process in compliance with clause 6 of ISO 27001:2022. In which standard is this process defined?

a)

ISO 31000:2018.

b)

ISO TEC 27002:2022.

c)

ISO 19011:2018.

d)

None of the above.

17.

With the GAP analysis:

4 lines
18.

The objectives of an ISMS are associated with confidentiality, integrity and availability of information. Confidentiality is the property that refers to:

a)

That the information can be accessed by the company's employees.

b)

That the information can be accessible at all times.

c)

Confidentiality does not refer to the authenticity and veracity of the information.

d)

Property of the information whereby it is kept inaccessible and not disclosed to unauthorized individuals, entities or processes.

19.

What are Information Security Objectives and what are they for?

a)

The objectives of an ISMS are the information security objectives for confidentiality, integrity and availability of information.

b)

Information security objectives help implement an organization's strategic goals and the information security policy.

c)

Information security objectives also help to specify and measure the performance of information security controls and processes in accordance with the information security policy.

d)

All of the above.

20.

As a lead implementer you know that you can take this standard as a guide for the design and implementation of an Information Security Management System:

a)

ISO 27003:2017.

b)

ISO IEC 27002: 2022.

c)

ISO 19011:2018.

d)

None of the above.

21.

You are working as a lead implementer of ISO/IEC 27001:2022 and supporting the definition of the information security policy. Some aspects that can be considered inputs for the security policy are the organization's purposes and objectives.

a)

True

b)

False

22.

You are working as lead implementer of ISO/IEC 27001:2022 and supporting the definition of the information security policy. Some aspects to keep in mind are:

a)

Understanding stakeholder needs and expectations.

b)

Internal needs.

c)

External needs (e.g. customers and users).

d)

All of the above.

23.

The documented information of an information security management system could consist of manuals, instructions, plans, formats, documented procedures, records and policies.

a)

True

b)

False

24.

What is the purpose of classifying information using control 5.12?

a)

Information shall be classified according to the organization's information security needs based on confidentiality, integrity, availability and relevant stakeholder requirements.

b)

Prevent unauthorized access to information.

c)

Assign information to an owner.

d)

Reduce the risk of human error.

25.

You are working as a Lead Implementer of an ISMS, in your experience, what could be an order to consider in the implementation?

a)

Define policy, define scope, assess risks, select controls, prepare a SOA (Statement of Applicability).

b)

Prepare a SOA (Statement of Applicability), define scope, define policy, assess risks, select controls.

c)

Define scope, define policy, assess risks, select controls, prepare a SOA (Statement of Applicability)

d)

Define scope, define policy, eliminate risks, prepare a SOA (Statement of Applicability), select controls.

26.

Establishing the organization's context and security policies, to which stage of the PDCA cycle do they belong?

a)

Act.

b)

Check.

c)

Do.

d)

Plan.

27.

What is a Statement of Applicability (SoA) and what is it for?

a)

This document is a requirement of the ISO/IEC 27001:2022 standard, it is the list of controls that are used, those that are not and the reasons why, as well as the evidence of their use.

b)

It is the list of the 4 control domains related to the risks.

c)

This document is a requirement of the ISO 31000:2018 standard, it relates risks, impacts, controls, scenarios and control objectives.

d)

This document is a requirement of the ISO/IEC 27001:2022 standard that determines the risks that apply to the organization in relation to the assessed information assets.

28.

You are working as a lead implementer of ISO/IEC 27001:2022 and you are going to deliver a document summarizing to top management the main aspects to consider for implementing an Information Security Management System (ISMS). What document are you preparing?

a)

Implementation Services Quotation.

b)

Audit Report.

c)

GAP Analysis.

d)

Business Case.

29.

Which of the following factors can affect scope determination according to clause 4.3 of ISO/IEC 27001:2022?

a)

External and internal issues described in 4.1.

b)

Stakeholders and their requirements determined in accordance with 4.2.

c)

The preparation of business activities to be included as part of the ISMS coverage.

d)

All of the above.

30.

How many approaches can be used to identify information security risks?

a)

Detection approach and risk mitigation approach.

b)

Event-based approach and approach based on the identification of assets, threats and vulnerabilities.

c)

It is recommended to use only one asset detection approach.

d)

All approaches are correct.

31.

The relationship between risks and controls is directly proportional, i.e. the higher the risk, the greater the need for controls. Risk assessment under ISO/EC 27001:2022 ensures that controls are not implemented where risks do not exist through risk treatment options, thus saving time and money. What are these risk treatment options?

a)

List risks, prioritize them based on risk value, address all risks.

b)

Avoid risk, assume risk, modify risk, share risk, retain risk.

c)

Eliminate risk, assume risk, modify risk, share risk, transfer risk.

d)

List risks, prioritize them based on asset value, treat the highest value first.

32.

You are working as a lead implementer of an ISMS and want to explain the most visible steps in the roadmap.

a)

Audit the current system, make a business case, hire the implementation.

b)

Business case, diagnosis, adopt a PDCA approach.

c)

Plan, make the business case, execute diagnostics and audit.

d)

Diagnosis, business case, adopt a PDCA approach.

33.

The most important purpose of information security policy is to provide the organization with direction and management support for information security

a)

False

b)

True

34.

The risk management process involves the systematic application of policies, procedures and practices to the activities of communication and consultation, setting the context and assessment, treatment, monitoring, review, recording and reporting of risk. What does an ISMS contribute to the organization through the risk management process?

a)

Determine the probability of a certain risk occurring.

b)

Determine appropriate controls to achieve acceptable levels of risk.

c)

Determine the damage caused by possible security-related incidents.

35.

The controls in Annex A have been regrouped into 4 domains. Which of these is an example of the "Physical Controls" domain?

a)

Store network equipment and electrical junction boxes in a locked room.

b)

Physical input.

c)

Segregation of Duties.

d)

Secure Coding.

36.

ISO/IEC 27002:2022 provides a reference set of generic information security controls, including an implementation guide:

a)

False

b)

Right

37.

The objectives of an ISMS are associated with confidentiality, integrity and availability of information. Availability is the property that refers to:

a)

That the information maintains the same data as in the last access.

b)

Property of the information by which it keeps the information accessible when needed.

c)

That the information is not stolen by a cybercriminal.

d)

All of the above.

38.

Who should require periodic review of ISMS performance reports?

a)

Top management.

b)

The person responsible for the ISMS.

c)

The lead implementer.

d)

The internal auditor.

39.

You are applying for a role as lead implementer of ISO/EC 27001:2022. During the interview you are asked: What is Information Security Risk Analysis? Select the best answer.

a)

The process for determining only the controls required to avoid compromising an information asset.

b)

It is the process to eliminate the risks of an information asset.

c)

Establishes the environmental safety risk of an organization.

d)

It is the process that includes the possible consequences that certain situations may bring with them and the probability that these will occur with the objective of measuring the level of risk.

40.

An example of a specific policy could be:

a)

Remote work, clean desktop and screen.

b)

Classification of information, secure authentication.

c)

Only A meets the criteria of a specific policy according to ISO IEC 27001:2022.

d)

A and B are examples for specific policies.