Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ISO IEC27001 2022 Assessment

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

What is the main purpose of an ISMS?

a)

To comply with regulations

b)

To minimize risk and ensure business continuity

c)

To control IT budgets

d)

To prevent staff turnover

2.

Which three principles form the “CIA Triad”?

a)

Confidentiality, Integrity, Availability

b)

Control, Identification, Access

c)

Confidentiality, Independence, Audit

d)

Clarity, Integrity, Authorization

3.

ISO/IEC 27001:2022 introduced which of the following changes?

a)

New Annex A controls

b)

Removal of all technical controls

c)

Elimination of risk assessment

d)

Expansion of scope to only IT

4.

Clause 5 of ISO/IEC 27001 relates to:

a)

Planning

b)

Leadership

c)

Support

d)

Risk Treatment

5.

Which document lists all applicable Annex A controls and whether they are implemented?

a)

Risk Register

b)

Statement of Applicability (SoA)

c)

Policy Manual

d)

Audit Checklist

6.

What is the role of top management in an ISMS?

a)

Provide oversight only

b)

Take accountability, provide resources, set direction

c)

Delegate all responsibility to IT

d)

Approve budgets once a year

7.

Which of the following is a new Annex A control?

a)

Teleworking

b)

Secure coding

c)

Anti-virus installation

d)

Password policy

8.

During a risk assessment, if a risk cannot be eliminated and the cost of treatment is higher than the potential impact, what is the correct approach?

a)

Transfer the risk

b)

Accept the risk

c)

Remove the activity

d)

Treat with all available controls

9.

What is the purpose of Annex A controls?

a)

Provide a fixed set of mandatory steps

b)

Offer a catalogue of best practice controls to support risk treatment

c)

Replace organizational policies

d)

Measure staff performance

10.

Which type of assessment involves scoring risks with numbers and probabilities?

a)

Qualitative

b)

Quantitative

c)

Hybrid

d)

Manual

11.

During an audit, you find that employees are accessing sensitive data on personal devices outside the office. The ISMS scope only covers office-based systems and excludes remote access. Which ISMS element is most relevant to address this gap?

a)

Scope definition

b)

Leadership commitment

c)

Documented information

d)

Risk acceptance

12.

A tax officer accidentally emails citizen data to the wrong recipient. This is primarily a breach of:

a)

Confidentiality

b)

Availability

c)

Integrity

d)

Resilience

13.

Your SOC team identifies an increase in phishing attempts. Which control is most relevant to address this risk?

a)

8.10 Information Deletion

b)

5.7 Threat Intelligence

c)

7.4 Physical Security Monitoring

d)

8.9 Configuration Management

14.

During an internal audit, you notice that procedures exist but staff are not following them. This shows a weakness in:

a)

Awareness

b)

Leadership

c)

Risk Assessment

d)

Scope

15.

Management wants assurance that the ISMS is effective and continually improving. Which cycle or principle supports this?

a)

SWOT analysis

b)

PDCA (Plan-Do-Check-Act) cycle

c)

PESTEL analysis

d)

Outsourcing controls