Module 1 - The Basics Flashcards

The Basics

1
Q

Name nine drivers for implementing ISO 27001

A

Client confidence

Avoid breaches and fines

Improve company culture

Secure information in all its forms

Manage information securely consistently

Protect the CIA of your data

Increase attack resilience

Respond to evolving threats

Reduce costs associated with info sec

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What year was the current ISO 27001 and 27002 standards updated?

A

2022

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What year was the previous ISO 27001 standard updated?

A

2013

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How many themes and controls are in ISO 27001:2022?

A

4 themes and 93 controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How many new controls were added in ISO 27001:2022?

A

11 new controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How long was the transition period between ISO 27001:2013 and ISO 27001:2022?

A

3 years

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a standard?

A

Specification that something can conform to, approved by a recognised body

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does a standard achieve?

A

Standards provide a reliable basis to review expectations about a product or service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Name the 6 Stages an ISO Standard goes through in order?

Mnem: Nutty …

A
  1. New standard / Revision
  2. WD – Working Draft
  3. CD – Committee Draft
  4. DIS – Enquiry Draft International Stage
  5. FDIS – Final Draft International Standard
  6. IS – International Standard adopted

Nutty Witches Chose Dry Figs Impressively

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the 5 types of stages an ISO standard goes through?

Mnem: Px-xxx

A
  1. Prepatory Stage
  2. Committee Stage
  3. Enquiry Stage
  4. Approval Stage
  5. Publication Stage

PC-EAP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does ISO stand for?

A

International Organisation of Standardisation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does IEC stand for?

A

International Electrotechnical Commission

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How does ISO decide what gets published?

A

Committee vote

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Through what means do ISO and IEC collaborate?

A

JTC – Joint Technical Committee

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does JTC stand for?

A

Joint Technical Committee, this is the means for collaboration between ISO and IEC

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the purpose of ISO?

A

To write International Standards

17
Q

What do ISO use as input for early standard drafts?

A

ISO take National Standards as input for first drafts of International Standards

18
Q

How long does it typically take for an ISO Standard to progress from WD to CD?

A

Usually around 3 years

19
Q

What are the 10 Sections of the ISO 27001 Standard?

Sxx-xxx-xxxx

A
  1. Scope
  2. Normal References
  3. Terms and Definitions
  4. Context of the Organisation
  5. Leadership
  6. Planning
  7. Support
  8. Operation
  9. Performance Evaluation
  10. Improvement

SNT-CLP-SOPI
Sent-Clip-Soppy

20
Q

What are the 9 ISMS Principles detailed for ISO 27000:2018 series?

Axx-xxxx-xx

A
  1. Awareness
  2. assignment of Responsibility
  3. incorporating management/stakeholder Commitment
  4. enhancing Societal values
  5. controls Proportional to risks
  6. security as an Essential element of networks and systems
  7. active prevention and Detection of incidents
  8. Comprehensive approach to information security management
  9. continual reassessment and Improvement

ARC-SPED-CI
Arc-Sped-Sea