Module 5 - Overview of ISO 27001 Flashcards

1
Q

What is a management system?

A

A management system uses a framework of resources to achieve an orgs objectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

In which ISO Standard and section is an ISMS defined?

A

ISO 27000:2018, section 3.2.5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Name 4 positive outcomes of implementing an ISMS?

A

Meet the orgs info sec objectives

Satisfy customer/stakeholder requirements

Comply with regulations

Manage risk and their risks in an organised manner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

In which ISO Standard and section is Implementing Security Controls outlined?

A

ISO 27000:2018, Section 4.5.5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What consideration should be made when choosing Security Controls?

A
  1. Regulations / Legislation
  2. Org objectives
  3. Operation requirements and constraints
  4. Cost proportional to risk
  5. How to monitor
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which section of ISO 27001 contains the Information Security Controls Reference?

A

Annex A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How many controls and themes are listed in Annex A?

A

93 controls in 4 themes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the 4 themes for Security Controls in Annex A?

A
  1. Organsiation - 37
  2. People - 8
  3. Physical - 14
  4. Technological – 34

Offensive Poets Pinched Turnips

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is ISO 27000:2018?

A

ISMS overview and defines vocabulary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is ISO 27001:2022?

A

Specification for an ISMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is ISO 27002:2022?

A

Catalogue of Security Controls described in detail

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is ISO 27003?

A

Covers implementation of an ISMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is ISO 27004?

A

Covers monitoring, analysis and evaluation of an ISMS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which Standards of the ISO 27000 family can you be certified against?

A

ISO 27001 is the only Standard you can be certified against

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What information does an ISO 27002 Control Description contain?

A
  1. Control Title - name
  2. Attribute table – value of attributes for a control
  3. Control – what the control is
  4. Purpose – when it should be used
  5. Guidance – how it should be implemented
  6. Other Info – other texts or refs

TAC-PG-O

How well did you know this?
1
Not at all
2
3
4
5
Perfectly