WorksheetsISO IEC27001 2022 Assessment
Total questions: 15
Worksheet time: 8mins
What is the main purpose of an ISMS?
To comply with regulations
To minimize risk and ensure business continuity
To control IT budgets
To prevent staff turnover
Which three principles form the “CIA Triad”?
Confidentiality, Integrity, Availability
Control, Identification, Access
Confidentiality, Independence, Audit
Clarity, Integrity, Authorization
ISO/IEC 27001:2022 introduced which of the following changes?
New Annex A controls
Removal of all technical controls
Elimination of risk assessment
Expansion of scope to only IT
Clause 5 of ISO/IEC 27001 relates to:
Planning
Leadership
Support
Risk Treatment
Which document lists all applicable Annex A controls and whether they are implemented?
Risk Register
Statement of Applicability (SoA)
Policy Manual
Audit Checklist
What is the role of top management in an ISMS?
Provide oversight only
Take accountability, provide resources, set direction
Delegate all responsibility to IT
Approve budgets once a year
Which of the following is a new Annex A control?
Teleworking
Secure coding
Anti-virus installation
Password policy
During a risk assessment, if a risk cannot be eliminated and the cost of treatment is higher than the potential impact, what is the correct approach?
Transfer the risk
Accept the risk
Remove the activity
Treat with all available controls
What is the purpose of Annex A controls?
Provide a fixed set of mandatory steps
Offer a catalogue of best practice controls to support risk treatment
Replace organizational policies
Measure staff performance
Which type of assessment involves scoring risks with numbers and probabilities?
Qualitative
Quantitative
Hybrid
Manual
During an audit, you find that employees are accessing sensitive data on personal devices outside the office. The ISMS scope only covers office-based systems and excludes remote access. Which ISMS element is most relevant to address this gap?
Scope definition
Leadership commitment
Documented information
Risk acceptance
A tax officer accidentally emails citizen data to the wrong recipient. This is primarily a breach of:
Confidentiality
Availability
Integrity
Resilience
Your SOC team identifies an increase in phishing attempts. Which control is most relevant to address this risk?
8.10 Information Deletion
5.7 Threat Intelligence
7.4 Physical Security Monitoring
8.9 Configuration Management
During an internal audit, you notice that procedures exist but staff are not following them. This shows a weakness in:
Awareness
Leadership
Risk Assessment
Scope
Management wants assurance that the ISMS is effective and continually improving. Which cycle or principle supports this?
SWOT analysis
PDCA (Plan-Do-Check-Act) cycle
PESTEL analysis
Outsourcing controls
