The ambition of the security manager is to certify the organization against ISO/IEC 27001.
What is an activity in the certification program?
Correct : D
Start a Discussions
The information security manager is writing the Information Security Management System (ISMS) documentation. The controls that are to be implemented must be described in one of the phases of the Plan-Do-
Check-Act (PDCA) cycle of the ISMS.
In which phase should these controls be described?
Correct : A
Start a Discussions
What needs to be decided prior to considering the treatment of risks?
Correct : A
Start a Discussions
Security monitoring is an important control measure to make sure that the required security level is maintained. In order to realize 24/7 availability of the service, this service is outsourced to a partner in the cloud.
What should be an important control in the contract?
Correct : D
Start a Discussions
What is the best way to start setting the information security controls?
Correct : C
Start a Discussions