ISO/IEC 27001

These questions cover the fundamentals of information security management systems (ISMS), controls, clauses, and compliance under ISO 27001.

fill the form  !

1 / 20

What is ISO/IEC 27001 primarily concerned with?

2 / 20

What does ISMS stand for?

3 / 20

Which of the following is NOT a core component of the ISO 27001 standard?

4 / 20

What is the purpose of Annex A in ISO 27001?

5 / 20

Which of the following is a mandatory clause in ISO 27001?

6 / 20

Clause 6 of ISO 27001 covers which aspect?

7 / 20

The “Plan-Do-Check-Act” (PDCA) cycle in ISO 27001 promotes:

8 / 20

Which of these is a control objective under ISO 27001 Annex A?

9 / 20

What must an organization define to handle risks under ISO 27001?

10 / 20

Who is ultimately responsible for information security in an organization?

11 / 20

ISO 27001 certification is mandatory for all organizations.

12 / 20

The Statement of Applicability is a mandatory document in ISO 27001.

13 / 20

Annex A contains recommended but optional controls.

14 / 20

Top management is not required to be involved in ISO 27001 implementation.

15 / 20

An internal audit is required as part of ISO 27001 compliance.

16 / 20

Information security policies are optional under ISO 27001.

17 / 20

The risk treatment plan is used to accept, avoid, transfer, or mitigate risks.

18 / 20

The “Check” phase in PDCA refers to risk identification.

19 / 20

ISO 27001 helps organizations meet compliance with other regulations like GDPR.

20 / 20

ISO 27001 focuses only on technical security controls.

Your score is

The average score is 0%

0%