ISO 27001

ISO/IEC 27001 Practitioner

Implementing an ISMS in practice: risk treatment, the Statement of Applicability, and continual improvement.

12 questions · 75% to pass · free

eurocompliant.com is not an accredited certification body. This is a self-paced educational assessment; the certificate confirms completion only, not a professional, statutory, or accredited qualification.

Your details

We'll email your certificate here if you pass. We may occasionally follow up about eurocompliant.com - you can unsubscribe any time.

Question 1 of 12

Under Clause 6.1.3, after identifying risks, what must an organisation do to treat them?

Question 2 of 12

Which of the following are recognised risk treatment options commonly referenced alongside ISO/IEC 27001 (via ISO 31000-aligned practice)?

Select all that apply.

Question 3 of 12

What is the relationship between the Statement of Applicability and Annex A?

Question 4 of 12

Under Clause 9.1, what must an organisation determine regarding monitoring and measurement of the ISMS?

Question 5 of 12

What is the purpose of a management review, as implied by the PDCA (Plan-Do-Check-Act) cycle underlying ISO/IEC 27001?

Question 6 of 12

Under Clause 7.2, what must an organisation do regarding competence of persons doing work affecting information security performance?

Question 7 of 12

Which Annex A control area would 'access control' most naturally fall under?

Question 8 of 12

What does 'continual improvement' under Clause 10.2 require of an organisation?

Question 9 of 12

An organisation can achieve ISO/IEC 27001 certification while excluding some Annex A controls, provided the exclusion is justified in the Statement of Applicability and does not affect the organisation's ability to meet its risk treatment decisions.

Question 10 of 12

What is the significance of Clause 4 ('context of the organisation') to the rest of the ISMS?

Question 11 of 12

How does an internal audit programme under Clause 9.2 typically relate to the certification (external) audit?

Question 12 of 12

Nonconformities identified during an ISO/IEC 27001 internal audit must always result in the organisation losing its certification.

0 of 12 answered