ISO 27000 Series Flashcards

1
Q

Which ISO contains guidelines for initiating, implementing, maintaining, and improving an ISMS within an organization. Organizational security standards and effective security management practices?

A

ISO 27002 (Code of Practice)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which ISO provides an Information Security Management System (ISMS) overview and vocabulary. Structure of an ISMS, ISO/IEC 27000 series explained and terminology defined?

A

ISO 27000 (Overview and Vocabulary)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which ISO explains the requirements for establishing, implementing, maintaining and continuously improving an ISMS. Requirements must be met for certification purposes?

A

ISO 27001 (Requirements)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which ISO explains the requirements for entities that certify ISMSs. Accreditation standard that guides certification bodies on the formal process they must follow when auditing an ISMS?

A

ISO 27006 (Certification Body Requirements)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which ISO provides guidelines for accredited certification bodies, internal auditors, external/third party auditors on how to audit an ISMS based upon the ISO 27001 requirements?

A

ISO 27007 (Audit Guidelines)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which ISO provides guidelines for ISMS implementation? How to build an ISO 27001 compliant ISMS. Scoring and defining boundaries, assessing risks, risk treatments, control requirements and implementation planning?

A

ISO 27003 (Implementation Guidance)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which ISO gives guidelines for security risk management? Identifying assets, threats, vulnerabilities, and impacts? Systems approach to risk analysis and developing a risk treatment plan?

A

ISO 27005 (Risk Management)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which ISO gives guidelines for security measurement? Guidance on the development and use of metrics and measurements in order to assess the effectiveness of an implemented ISMS?

A

ISO 27004 (Measurements)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which ISO provides guidelines on security management for telecommunications organizations? Development and managing an ISMS within the context of the telecommunication’s overall business risks?

A

ISO 27011 (Telecommunications Organizations)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which ISO gives guidelines for health informatics? Best practice guidelines and a set of controls for managing health information security?

A

ISO 27799 (Health Organizations)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly