ISO/IEC 27001 (2022) Foundation Exam Questions and Answers
Which action is a required response to an identified residual risk?
Which activity is a required element of information security risk identification?
Which factor is required to be determined when understanding the organization and its context?
Which International Standard can be used to implement an integrated management system with ISO/IEC 27001?
To whom are the information security policies required to be communicated, according to the control in Annex A of ISO/IEC 27001?
Which statement describes a requirement of an internal audit programme?
Which item is required to be considered when defining the scope and boundaries of the information security management system?
Identify the missing word(s) in the following sentence.
When planning the ISMS, the organization is specifically required to plan actions to address risks and opportunities and how to [ ? ] these actions.
What is the definition of a threat according to ISO/IEC 27000?
Identify the missing words in the following sentence.
The organization shall establish, implement, maintain and [ ? ] an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document.
Which statement is a factor that will influence the implementation of the information security management system?
Which ISMS documentation is part of the minimum scope of documented information required to be managed and controlled?
Identify the missing word(s) in the following sentence.
“Information security, cybersecurity and privacy protection – [ ? ]” is the title of ISO/IEC 27005.
Which attribute is NOT a required focus of continual ISMS improvement?
Which statement describes Annex A of ISO/IEC 27001?