Lead Auditor 27001 Flashcards
Information is what kind of asset?
Strategic
Property of accuracy and completeness. CIA triad
Integrity
CIA Triad
Confidential
Integrity
Availability
A hacker compromising a message someone sends to another is what CIA?
Integrity, accuracy of message was corrupted
When someone sends a message and they can no longer claim they didn’t is what?
Non repudiation
Property is the entity it claims to be
Authenticity
Example of authentic and non repudiation
Digital signature
Use a framework of resources to achieve an organization’s objectives
Management systems
Management system components
Quality management
Scope
Organization
Process
Policies
Records
PDCA cycle
In the quality management:
Plan
Do
Check
Act
Management system used to ensure the information security of its information assets
ISMS
In sec man sys
Item of value to an org is a primary asset
False, information asset
Primary is business process
Stand. That specifies requirements for estáb implementation and manage. And continual improving of ISMS
ISO 27001
Catalog of security and privacy controls for all U.S. federal information systems
Nist 800-53
Framework for governance and manage of enterprise IT
Cobit 2019
Only normative standards like 27001 can be audited
True
Nist framework is what 5?
Identify
Protect
Detect
Respond
Recover
6th is governance
Standard that contains guidelines for implementing security controls
27002
Clause 7.5
Documented information
Which clause requires org to include documented information in the ISMS as directly required by 27001 and org for effectiveness of the ISMS
7.5
Documentation life cycle
Créate
Store
Use
Archive
Dispose
12 step method
Management support
Scope of ISMS
Gap Analysis
Information security policy
Competence assurance
Asset inventory
Risk management methodology
Risk assessment
Risk treatment
Performance evaluation
Improvement
Certification audit
Determines whether a project is worth it
Business case
Raci matrix
Responsible
Accountable
Consulted
Informed
Most important reason to obtain support by top management for an ISO 27001 implementation project
Guarantee sufficient resources and budget for the implementation
Responsibility specifically for top management in ISO 27001
Approving information security policy
True or false, multiple roles can be assigned accountability role within an activity
False
Name a standard that is normative and can be certified
27001
A procedures describing how to configure a server is an example of?
Document
3 purposes of context analysis
Scope of isms
Risk and opportunities
Adaptation
Pestel
Political
Economical
Social
Technological
Environmental
Legal
4.4
Org estab implements and maintains continuous improvement of ISMS
Only 2 process required in ISO 27001
Risk assessment
Risk treatment
This has to be available as documented information due to requirements of ISO 27001
Scope of ISMS
A customer requiring an org to have compliance with privacy regulations is defined as what?
Interested party
Who is accountable for approving scope of ISMS?
Top management
Org establishes information security objectives and plans to achieve them at relevant functions and levels
6.2
Info sec objectives
Strategic goals
Is policy
Confidential
Integrity
Availability
Smart goals
Specific
Measure able
Achieve able
Relevant
Timebound
Management systeme used to ensure the information security of its information assets
ISMS
Primary assets are an item of value to the org
False, information assets
Primary is business processes and activities information
Supporting assets- enable primary assets
4 tabs to track assets
Classification
Type
Category
Owner
This consists of leadership, org structure and process that ensure enterprises IT sustains and extends the enterprise strategies and objectives
IT governance
3 benefits of IT governance
Benefits realization
Risk optimization
Resource optimization
Resource optimization treats risks to meet an org risk acceptance criteria
False, risk optimization
-Resource optimization is the provision of necessary resources and training for efficient tech use
Benefits realization is IT creates value aligned with org values and measure for success and eliminate low value initiatives