Big Cyber Monday Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the APMG-International ISO/IEC 27001 ISO-IEC-27001-Foundation Questions and answers with CertsForce

Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions
Questions # 11:

Identify the missing word(s) in the following control relating to the Policies for information security control.

“Information security policy and topic-specific policies should be defined, approved by management, [ ? ] and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur.”

Options:

A.

published


B.

established and maintained


C.

published, communicated to


D.

communicated to


Expert Solution
Questions # 12:

Which statement describes the Classification of information control in Annex A of ISO/IEC 27001?

Options:

A.

Ensures that all information assets are labelled with their classification


B.

Ensures that information is classified based on confidentiality, integrity and availability


C.

Ensures that security perimeters are used to protect assets


D.

Ensures the rules to control physical and logical access apply to assets


Expert Solution
Questions # 13:

To whom does the scope of the Terms and conditions of employment control apply?

Options:

A.

Employees only


B.

Contractors only


C.

Personnel and the organization


D.

All employees, contractors and third-party users


Expert Solution
Questions # 14:

Which action is a required response to an identified residual risk?

Options:

A.

By default, it shall be controlled by information security awareness and training


B.

Top management shall delegate its treatment to risk owners


C.

It shall be reviewed by the risk owner to consider acceptance


D.

The organization shall change practices to avoid the risk occurring


Expert Solution
Questions # 15:

Which statement is a factor that will influence the implementation of the information security management system?

Options:

A.

The ISMS will be separate from the organization's overall management structure


B.

The ISMS will encompass all controls specified within ISO/IEC 27001


C.

The ISMS will be scaled to the controls according to the needs of the organization


D.

The ISMS will be operated as an independent process within the organization


Expert Solution
Viewing page 2 out of 2 pages
Viewing questions 11-20 out of questions