Which trend in information security performance is required to be considered during a management review of the ISMS?
Answer : A
Clause 9.3.2 (Management Review Inputs) states that management reviews shall include:
''c) information on the information security performance, including trends in: (1) nonconformities and corrective actions; (2) monitoring and measurement results; (3) audit results; and (4) fulfilment of information security objectives.''
This makes achievement of information security objectives (option A) a required trend to be considered. While external/internal requirements (C) and continual improvement opportunities (D) are also part of management review inputs, they are not specifically listed under ''trends in performance.'' Option B is outside the direct requirement.
Thus, the verified answer is A.
Identify the missing word in the following sentence.
The organization shall determine the [ ? ] of interested parties relevant to information security.
Answer : A
Clause 4.2 of ISO/IEC 27001:2022 states:
''The organization shall determine: a) interested parties that are relevant to the information security management system; b) the relevant requirements of these interested parties; c) which of these requirements will be addressed through the ISMS.''
This confirms that the missing word is requirements. Neither number, structure, nor influence are specified in the standard.
What international standard provides guidance on the integration of ISO/IEC 27001 and the IT Service Management standard?
Answer : B
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27013 standards:
ISO/IEC 27013 is titled:
''Information technology --- Security techniques --- Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1.''
This standard provides organizations with specific advice on how to integrate an Information Security Management System (ISMS) with an IT Service Management System (ITSMS). ISO/IEC 20000-1 is the IT Service Management requirements standard, but integration guidance is provided in 27013. ISO/IEC 27002 (A) is guidance for controls, not integration. Option D is incorrect since ISO/IEC 27013 explicitly exists for this purpose.
Therefore, the correct verified answer is B: ISO/IEC 27013.
What is the name of the control clause used to control information security breaches within Annex A of ISO/IEC 27001?
Answer : A
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
Annex A in ISO/IEC 27001 refers directly to ISO/IEC 27002 for control guidance. In ISO/IEC 27002:2022, Clause 6.8 is titled:
''Information security event reporting -- Information security events should be reported through appropriate management channels as quickly as possible.''
This control ensures breaches, incidents, or suspected issues are reported for action. The other options (B, C, D) are not the exact titles in Annex A. The official title is Information security event reporting, confirming Answer: A.
Which International Standard can be used to implement an integrated management system with ISO/IEC 27001?
Answer : B
ISO/IEC 27013 provides specific guidance on the integration of ISO/IEC 27001 (Information Security Management) and ISO/IEC 20000-1 (IT Service Management). It offers practical advice for organizations seeking a unified management system approach. While ISO/IEC 27003 (A) provides guidance on ISMS implementation, it does not address integration. ISO 9001 (C) is the Quality Management Standard and can be integrated, but the specific standard designed for integrating 27001 with ITSM is ISO/IEC 27013.
Therefore, the correct answer is B: ISO/IEC 27013, as it is explicitly published for this purpose.
When are the information security policies required to be reviewed, according to the Policies for information security control?
Answer : D
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
Annex A.5.1 (Policies for information security) specifies:
''Information security policy and topic-specific policies should be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur.''
This clearly identifies the review frequency requirement: planned intervals and whenever there are significant changes. Options A and B (six-monthly or annually) are not prescribed by ISO --- timing is left to the organization. Option C is also wrong, since Certification Bodies do not dictate policy review schedules.
Therefore, the verified correct answer is D.
Identify the missing word(s) in the following control relating to the Policies for information security control.
''Information security policy and topic-specific policies should be defined, approved by management, [ ? ] and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur.''
Answer : C
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
Annex A.5.1 (Policies for information security) states:
''Information security policy and topic-specific policies should be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur.''
This confirms that the missing words are ''published, communicated to.'' The control emphasizes not just defining and approving policies but ensuring they are actively distributed and communicated so that relevant stakeholders are aware of and acknowledge them. Options A, B, and D are partial but incomplete.
Thus, the correct answer is C.