wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Day#2B LA Certiprof

Total questions: 20

Worksheet time: 17mins

Name
Class
Date
1.

Which activity summarizes the ACT phase of the PDCA in an information security management system?

a)

Monitor the ISMS.

b)

Review the entire ISMS and issue findings.

c)

Continuous improvement.

d)

Internal audit and issue findings.

2.

To comply with the requirement of ISO/EC 27001:2022 we must establish a program of internal audits that allow us to review the ISMS. What is the purpose of an audit program?

a)

Obtain objective evidence and evaluate it objectively to determine the extent to which the audit criteria are met.

b)

Ensure that all controls are aligned to the standard and check that the ISMS we have implemented complies with the wishes of top management.

c)

Provide information on whether the ISMS meets the organization's own requirements for its ISMS as well as those of ISO/IEC 27001:2022.

d)

Define the structure and responsibilities for planning, conducting, reporting and monitoring on individual audit activities to ensure appropriate scope, minimize impact on operations, and maintain required audit quality.

3.

Executing processes, collecting records and evaluating the consequences on planned and unplanned changes as a result of the planning phase belong to which stage of the PDCA cycle?

a)

Act.

b)

Do.

c)

Plan.

d)

Check.

4.

What is the purpose of incident management using control 5.26?

a)

Information security incidents shall be responded to in accordance with documented procedures.

b)

Always ensure that information security incident management is implemented given its global importance.

c)

Comply with the requirements of ISO/IEC 27002.

d)

Comply with the information security policy.

5.

You are working as a Lead Auditor of ISO/IEC 27001:2022. You recommend evaluating the update of the current Statement of Applicability (SoA). Why is this update recommendation being made?

a)

Because it is updated after each event.

b)

Because the standard requires an update every 3 months.

c)

Because risks are not eliminated.

d)

Because risks are constantly evaluated and updated.

6.

You have been consulted by a team working on the implementation of an ISMS. What document is produced after conducting a GAP analysis?

a)

Action plan.

b)

Audit checklist.

c)

Statement of applicability.

d)

Business case.

7.

You are working as a Lead Auditor of ISO/IEC 27001:2022 in the role of an external consultant. Staff of the company you are working for consult you on what would be the requirements and conditions for defining the scope of the information security management system (ISMS). Select those that apply:

a)

B. Consider the requirements and expectations of interested parties.

b)

A. Consider the analysis of the organization's context (external and internal issues).

c)

C. Define the scope only when you have selected the controls to implement and the SoA.

d)

A and B correct

8.

As the lead implementer of ISO/IEC 27001:2022, you recommend establishing a hierarchy of policies for the definition of information security policies. What are the levels you would recommend following?

a)

A. High level, IS policy, specific policies.

b)

B. Management and operational policies.

c)

C. Combination of A and B.

d)

D. None of the above.

9.

What is the purpose of controlling the transfer of information using control 5.14?

a)

Always ensure that the control is implemented given its global importance in the transfer of information that occurs naturally today.

b)

The only valid purpose for implementing this control is to avoid non-compliance with legal obligations such as the personal data protection law.

c)

Comply with the requirements of ISO/IEC 27002.

d)

Establish information transfer rules, procedures or agreements for all types of transfer facilities within the organization and between the organization and other parties.

10.

As Lead Auditor of ISO/IEC 27001:2022 you are commenting the definition of the information security policy. Some aspects to keep in mind are:

a)

Understanding stakeholder needs and expectations.

b)

Only internal needs because it is a business management system.

c)

Only external needs because the aim is to protect customer and user information.

d)

None of the above.

11.

Control 5.9, Inventory of information and other associated assets, is considered:

1. Inventory.

2. Owners of the assets.

3. Information transfer.

a)

Only 1 and 2 are correct.

b)

Only 3 is correct.

c)

Only 1 and 3 are correct.

d)

All options are related to control.

12.

What is the categorization of Annex A in ISO IEC 27001:2022?

a)

Annex A divides the 93 controls into 4 themes: Political, Financial, Cultural and Legal.

b)

Annex A divides the 93 controls into 4 themes: Organizational, People, Physical and Technological.

c)

Annex A divides the 93 controls into 4 themes: Organizational, Human, Physical and Technological.

d)

Annex A continues with the same structure of its predecessor ISO IEC 27001:2013.

13.

The ISO/EC 27001:2022 standard establishes as a requirement, the need to define an Information Security Policy appropriate to the needs of the organization. Select the best answer that complements this definition.

a)

Describes the strategic importance of the information security management system for the organization and shall be available as documented information.

b)

It is a document that establishes in writing the "when" and "how" an organization plans to protect its information and information assets. The Information Security Policy is a living document, so it should be reviewed every six months to ensure that it is adequate to the needs.

c)

Establishes the implementation and monitoring guide of the ISMS. The Information Security Policy must be protected to prevent all company employees from knowing about it.

d)

A document that establishes in writing the "why" and "when" an organization plans to protect its information and information assets.

14.

As a Lead ISMS Auditor you must evaluate a risk assessment and risk treatment process in compliance with clause 6 of ISO 27001:2022. In which standard is this process defined?

a)

ISO 31000:2018.

b)

ISO TEC 27002:2022.

c)

ISO 19011:2018.

d)

None of the above.

15.

With the GAP analysis:

a)

We build the business case, provides us with the reasons why an ISMS should be implemented and approximate the cost and effort to implement an ISMS.

b)

The GAP analysis is expected to provide the current status of the information security practices implemented, i.e. the "gap" between the requirements of ISO/IEC 27001:2022 and the current practices will be known, in order to generate a gap closure plan.

c)

We can obtain the approximate financial cost of gap closure.

d)

The direct relationship between the previous and current state of the organization is established.

16.

The objectives of an ISMS are associated with confidentiality, integrity and availability of information. Confidentiality is the property that refers to:

a)

That the information can be accessed by the company's employees.

b)

That the information can be accessible at all times.

c)

Confidentiality does not refer to the authenticity and veracity of the information.

d)

Property of the information whereby it is kept inaccessible and not disclosed to unauthorized individuals, entities or processes.

17.

What are Information Security Objectives and what are they for?

a)

The objectives of an ISMS are the information security objectives for confidentiality, integrity and availability of information.

b)

Information security objectives help implement an organization's strategic goals and the information security policy.

c)

Information security objectives also help to specify and measure the performance of information security controls and processes in accordance with the information security policy.

d)

All of the above.

18.

As a Lead Auditor you know that you can take this standard as a guide for the design and implementation of an Information Security Management System:

a)

ISO 27003:2017.

b)

ISO IEC 27002: 2022.

c)

ISO 19011:2018.

d)

None of the above.

19.

You are working as a Lead Auditor of ISO/IEC 27001:2022 and review the definition of the information security policy. Some aspects that can be considered inputs for the security policy are the organization's purposes and objectives.

a)

True.

b)

False.

20.

You are working as lead implementer of ISO/EC 27001:2022 and supporting the definition of the information security policy. Some aspects to keep in mind are:

a)

Understanding stakeholder needs and expectations.

b)

Internal needs.

c)

External needs (e.g. customers and users).

d)

All of the above.