Module 3 Flashcards
Context of the Organisation
1
Q
what are the first 3 clauses in ISO27001 and what is special about these?
A
1: scope
2. normative references
3. terms and definitions
these first 3 clauses are not part of an audit
2
Q
what is Integrity in the CIA triad?
A
integrity is about Data Accuracy (genuine) and Completeness
-> Information cannot be altered without authorisation
3
Q
what is Availability in the CIA triad?
A
information must be accessible when required
4
Q
what is the purpose of the ISMS?
A
- understand the orgs needs for infosec
- implement and operate controls
- monitor and review the performance and effectiveness of the ISMS
- continual improvement
5
Q
A