Diederik Merkens
Quiz von , erstellt am more than 1 year ago

This is the first quiz about 27002

3624
0
0
Diederik Merkens
Erstellt von Diederik Merkens vor mehr als 4 Jahre
Schließen

ISO 27002 quiz part 1

Frage 1 von 10

1

What does the Information Security Policy describe?

Wähle eine der folgenden:

  • which InfoSec-controls have been selected and taken

  • how the InfoSec-objectives will be reached

  • what the implementation-planning of the information security management system is

  • which Information Security-procedures are selected

Erklärung

Frage 2 von 10

1

Wähle von der Aufklappliste, um den Text zu vervollständigen.

In the context of contact with special interest groups, any information sharing agreements should identify requirements for the protection of ( topic-specific, public, confidential ) information.

Erklärung

Frage 3 von 10

1

Responsibilities for information security in projects should be defined and allocated to:

Wähle eine der folgenden:

  • the project manager

  • specified roles defined in the used project management method of the organization

  • the InfoSec officer

  • the owner of the involved asset

  • the manager of the business domain in which the project is carried out

Erklärung

Frage 4 von 10

1

Organizations allowing teleworking activities, the physical security of the building and the local environment of the teleworking site should be considered

Wähle eins der folgenden:

  • WAHR
  • FALSCH

Erklärung

Frage 5 von 10

1

Wähle von der Aufklappliste, um den Text zu vervollständigen.

Prior to employment, ( screening, awareness training, trial period ) as well as terms & conditions of employment are included as controls in ISO 27002 to ensure that employees and contractors understand their responsibilities and are suitable for the roles for which they are considered.

Erklärung

Frage 6 von 10

1

It is allowed that employees and contractors are provided with an anonymous reporting channel to report violations of information security policies or procedures (“whistle blowing”)

Wähle eins der folgenden:

  • WAHR
  • FALSCH

Erklärung

Frage 7 von 10

1

The identified owner of an asset is always an individual

Wähle eins der folgenden:

  • WAHR
  • FALSCH

Erklärung

Frage 8 von 10

1

Who is accountable to classify information assets?

Wähle eine der folgenden:

  • the CEO

  • the CISO

  • the asset owner

  • the Information Security team

Erklärung

Frage 9 von 10

1

Wähle von der Aufklappliste, um den Text zu vervollständigen.

Physical labels and ( data encryption, metadata, digital folders ) are two common forms of labelling which are mentioned in ISO 27002.

Erklärung

Frage 10 von 10

1

What should be used to protect data on removable media if data confidentiality or integrity are important considerations?

Wähle eine der folgenden:

  • backup on another removable medium

  • a password

  • logging

  • cryptographic techniques

Erklärung