ISO 27001 FOUNDATION ALL QUESTIONS AND
ANSWERS SURE A+
✔✔Who should approve the risk treatment plan? - ✔✔The risk owners
✔✔What should be included in the supplier agreements regarding information security -
✔✔Information at risk, legal and regulatory requirements, non disclosure agreement-- or
all the above
✔✔Which clause of ISO/IEC 27001 is part of the plan phase of the PDCA cycle? -
✔✔Context
✔✔Which of the following statement about information security objectives is correct ?
Information security objectives should be :
1-Established and communicated to all employees
2-Aligned with security policy
3-Reviewed every six months
4-Documented
5-Measurable - ✔✔2-Aligned with security policy
4-Documented
5-Measurable
✔✔Interested parties relevant to the ISMS need to be identified in order to -
✔✔Understand the context of the organization
✔✔ What does the organization need to consider when determining the ISMS scope? -
✔✔The internal issues, the requirements of interested parties, and external issues
✔✔What is the purpose of ISO 27001? - ✔✔Providing the requirements of the ISMS
development and operation
ANSWERS SURE A+
✔✔Who should approve the risk treatment plan? - ✔✔The risk owners
✔✔What should be included in the supplier agreements regarding information security -
✔✔Information at risk, legal and regulatory requirements, non disclosure agreement-- or
all the above
✔✔Which clause of ISO/IEC 27001 is part of the plan phase of the PDCA cycle? -
✔✔Context
✔✔Which of the following statement about information security objectives is correct ?
Information security objectives should be :
1-Established and communicated to all employees
2-Aligned with security policy
3-Reviewed every six months
4-Documented
5-Measurable - ✔✔2-Aligned with security policy
4-Documented
5-Measurable
✔✔Interested parties relevant to the ISMS need to be identified in order to -
✔✔Understand the context of the organization
✔✔ What does the organization need to consider when determining the ISMS scope? -
✔✔The internal issues, the requirements of interested parties, and external issues
✔✔What is the purpose of ISO 27001? - ✔✔Providing the requirements of the ISMS
development and operation