You are on page 1of 1

CLASS TEST ON ISO/IEC 27001:2013 INFORMATION SECURITY MANAGEMENT SYSTEM

Name of Participant: ………………………………………………… Employee No: ………………. Date of Test: ……./……./……

[ Please tick mark the correct answer only. Each question carries 10 marks each. Total 100 marks. Time : 5 minutes ]

Q-01) ISO/IEC 27001:2013 standard was developed by …

(a) International Organisation for Standardisation (b) Microsoft (c ) Google

Q-02) Which standard spells out the requirements for information security management system ?

(a) ISO/IEC 27000:2014 (b) ISO/IEC 27001:2013 ( c ) ISO/IEC 27002:2013

Q-03) “The property of being accessible and usable upon demand by an authorized entity’’ is called …

(a) Confidentiality (b) Availability ( c ) Dependability

Q-04) “The property that information is not made available or disclosed to unauthorized individuals, entities,
or processes” is called …

(a) Integrity (b) Security ( c ) Confidentiality

Q-05) “Process to comprehend the nature of risk and to determine the level of risk” is called …

(a) Risk Acceptance (b) Risk Analysis ( c ) Risk Evaluation

Q-06) “A weakness of an asset or control that can be exploited by one or more threats” is called …

(a) Threat (b) Vulnerability

Q-07) The ISMS documentation shall include ‘risk treatment plan’. Is this statement true or false ?

(a) True (b) False

Q-08) Visitors’ book, audit reports and completed access authorization forms are examples of …

(a) ISMS records (b) ISMS instructions

Q-09) “There shall be a formal disciplinary process for employees who have committed a security breach”. True or false ?

(a) True (b) False

Q-10) Who shall ensure that unattended user equipment has appropriate protection ?

(a) Users (b) Organization

Total Marks = 100

Marks obtained = …………….

Test Result : PASS / FAIL

You might also like