ISO 27001 – ISMS PRACTICE EXAM
ISO 27001 (process) - ANSWER Process Steps:
1. Security Policy
2. Define ISMS Scope
3. Conduct a risk assessment
4. Manage identified risks
5. Select control objectives & controls for implementation
6. Statement of applicability
PS1 - ANSWER Security Policy
SoA (ISO 27001 - Statement of Applicability) - ANSWER Defines the
INFOSEC controls and organization's approach to meeting them or
rationale(s) for omissions
PS2 - ANSWER Define ISMS Scope
PS3 - ANSWER Conduct a risk assessment
PS4 - ANSWER Manage identified risks
PS5 - ANSWER Select control objectives & controls for implementation
PS6 - ANSWER Statement of applicability
ISO 27001 (description) - ANSWER Security standard that formally
specifies an Information Security Management System (ISMS) that is
intended to bring information security under explicit management
control.
ISO 27001 (process) - ANSWER Process Steps:
1. Security Policy
2. Define ISMS Scope
3. Conduct a risk assessment
4. Manage identified risks
5. Select control objectives & controls for implementation
6. Statement of applicability
PS1 - ANSWER Security Policy
SoA (ISO 27001 - Statement of Applicability) - ANSWER Defines the
INFOSEC controls and organization's approach to meeting them or
rationale(s) for omissions
PS2 - ANSWER Define ISMS Scope
PS3 - ANSWER Conduct a risk assessment
PS4 - ANSWER Manage identified risks
PS5 - ANSWER Select control objectives & controls for implementation
PS6 - ANSWER Statement of applicability
ISO 27001 (description) - ANSWER Security standard that formally
specifies an Information Security Management System (ISMS) that is
intended to bring information security under explicit management
control.