2 - ISMS and the ISO 27001 Standards Family Flashcards

1
Q

Critical factors to ans ISMS

A

CIA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Key components for IS policy

A

Process / procedure
Technology
User behaviour

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Project Plan - Documentation - 11 sections

A
  • Business continuity planning
  • System acquisition, development and maintenance
  • IS incident management
  • Communication and operations management
  • Physical and environmental security
  • Personal security
  • System access control
  • Security policies
  • Security organisation
  • Compliance
  • Asset classification and control
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Project Plan - Decision making

A
  • Existing IT maturity levels
  • Customer requirements
  • Existing training programs
  • Business objectives and priorities
  • Adherence to internal processes
  • Internal audit capability
  • Existing compliance efforts and legal requirements
  • The entreprise’s ability to adapt to change
  • User acceptability and awarness
  • Contractual obligations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

PDCA meaning

A

Plan - do - check - act

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

PDCA steps

A

ISMS policy
scope of the ISMS
Perform a security risk assessment
Manage the identified risk
Select controls to be implemented and applied
Prepare an SOA (statement of applicability)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

SOA meaning

A

statement of applicability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The eleven phases of Implementation

A

Identify Business Objectives
Obtain Management Support
Select the proper scope of implementation
Define a method of risk assessment
Prepare an inventory of information assets to protect, and rank them according to risk based on risk assessment
Manage the risks, and create a risk treatment plan
Set up policies and procedures to control risks
Allocate resources, and train the staff
Monitor the implementation of the ISMS
Prepare for the certification audit
COnduct periodic reassessment audits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

The governing principle behind an ISMS is …

A

an organisation should design, implement and maintain a coherent set of policies, processes and systems to manage risks to its information assets

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Process Approach - Phase 1

A

Scope, design and build

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Process Approach - Phase 2

A

First cycle of implementation, operation, monitoring and improvement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Process Approach - Phase 3 (BAU)

A

Operate, monitor and improve

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Define what is a BAU

A

When the integration of the ISMS processes and controls are complete, the ISMS becomes a BAU (Business as Usual) system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Define what is a BAU

A

When the integration of the ISMS processes and controls are complete, the ISMS becomes a BAU (Business as Usual) system

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

PDCA - plan

A

policy, ISMS process, procedures and objectives for risk management and improvement of IS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

PDCA - do

A

implement and exploit ISMS policy, controls, processes and procedures

17
Q

PDCA - check

A

assess the performances, policies and practical experience and report the result for management review

18
Q

PDCA - act

A

Update and improve the system