ISO 27001 - What & Why Flashcards

1
Q

What is a common misconception about ISO 27001?

A

Many believe ISO 27001 provides detailed instructions on specific security measures, such as backup frequency or technology configurations. In reality, it defines a framework for managing risks but leaves implementation details to organizations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ISO 27001 does not provide specific technical instructions but rather a _____ for managing risks.

A

framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does ISO 27001 approach information security implementation?

A

ISO 27001 requires organizations to identify applicable requirements and select appropriate controls based on risk assessment results, rather than prescribing specific controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Organizations must select _____ based on risk assessment results, rather than following a fixed list of controls.

A

appropriate security controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the role of risk assessment in ISO 27001?

A

Risk assessment helps determine necessary security controls by identifying potential threats and vulnerabilities that could impact the organization’s information security.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A _____ is crucial in determining necessary security controls by identifying threats and vulnerabilities.

A

risk assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Does ISO 27001 mandate specific information security controls?

A

No, ISO 27001 does not mandate specific controls; organizations must choose controls based on their unique risks and requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

ISO 27001 _____, but allows organizations to tailor them based on their risk profile.

A

does not mandate specific controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the purpose of an Information Security Management System (ISMS) in ISO 27001?

A

An ISMS provides a systematic approach to managing sensitive company information, ensuring its confidentiality, integrity, and availability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

An ISMS ensures _____ of information.

A

confidentiality, integrity, and availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

How does ISO 27001 ensure continuous improvement in information security?

A

ISO 27001 promotes continuous improvement through regular monitoring, reviews, and updates to the ISMS based on evolving risks and business needs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

_____ in ISO 27001 is achieved through monitoring, reviews, and updates to the ISMS.

A

Continuous improvement

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the significance of the Plan-Do-Check-Act (PDCA) cycle in ISO 27001?

A

The PDCA cycle ensures that the ISMS is effectively implemented, maintained, and continually improved.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

The _____ helps organizations implement and improve their ISMS.

A

Plan-Do-Check-Act (PDCA) cycle

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

How does ISO 27001 address legal and regulatory requirements?

A

Organizations must identify and assess applicable legal, regulatory, and contractual requirements to ensure compliance within their ISMS.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ISO 27001 requires organizations to identify and comply with _____ related to information security.

A

legal, regulatory, and contractual requirements

17
Q

Why is top management support crucial in ISO 27001 implementation?

A

Top management support ensures adequate resources, promotes a culture of security, and aligns information security objectives with business goals.

18
Q

_____ is crucial for providing resources and aligning security with business objectives.

A

Top management support

19
Q

How does ISO 27001 handle documentation requirements?

A

ISO 27001 requires organizations to maintain documented information to support the operation of the ISMS and provide evidence of compliance.

20
Q

Documentation in ISO 27001 is required to _____.

A

support ISMS operations and provide compliance evidence