What international standard provides guidance on the integration of ISO/IEC 27001 and the IT Service Management standard?
When are the information security policies required to be reviewed, according to the Policies for information security control?
What activity is done first when preparing for an initial certification audit?
Which item is required to be defined when planning the organization's risk assessment process?
Which trend in information security performance is required to be considered during a management review of the ISMS?
Identify the missing word in the following sentence.
According to ISO/IEC 27000, the definition of risk [?] is a “process to comprehend the nature of risk and to determine the level of risk.”
Which action is a required response to an identified residual risk?
Which statement describes Annex A of ISO/IEC 27001?
Identify the missing word(s) in the following sentence.
“Information security, cybersecurity and privacy protection – [ ? ]” is the title of ISO/IEC 27005.
Which statement describes a purpose of monitoring, measurement, analysis and evaluation according to ISO/IEC 27001?
What is required to be reported by the Information security event reporting control?
Which action is an organization required to take to ensure that personnel are competent to perform their assigned tasks within the ISMS?
Which ISMS documentation is part of the minimum scope of documented information required to be managed and controlled?
In an audit, what is the definition of an observation?
Which item is required to be included in an information security policy?