Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Exam (elaborations)

IBITGQ - ISO CERTIFIED ISMS LEAD IMPLEMENTER (CIS LI) CERTIFICATION EXAM QUESTIONS AND FULL CORRECT ANSWERS (NEW UPDATED

Rating
-
Sold
-
Pages
27
Uploaded on
18-06-2025
Written in
2024/2025

IBITGQ - ISO CERTIFIED ISMS LEAD IMPLEMENTER (CIS LI) CERTIFICATION EXAM QUESTIONS AND FULL CORRECT ANSWERS (NEW UPDATED....

Institution
IBITGQ - ISO CERTIFIED ISMS LEAD IMPLEMENTER
Course
IBITGQ - ISO CERTIFIED ISMS LEAD IMPLEMENTER

Content preview

300 QUESTIONS AND ANSWERS


1. What is the primary purpose of an Information Security Management
System (ISMS)? Answer: To provide a systematic approach to managing
sensitive company information and ensuring it remains secure through the
implementation of a framework of policies, procedures, and controls.
2. Which ISO standard specifically addresses Information Security
Management Systems? Answer: ISO 27001:2022 (previously ISO
27001:2013)
3. What does ISMS stand for? Answer: Information Security Management
System
4. What are the three fundamental principles of information security (CIA
Triad)? Answer: Confidentiality, Integrity, and Availability
5. Define Confidentiality in the context of information security. Answer:
Ensuring that information is accessible only to those authorized to have access
to it.
6. Define Integrity in information security. Answer: Safeguarding the
accuracy and completeness of information and processing methods.
7. Define Availability in information security. Answer: Ensuring that
authorized users have access to information and associated assets when
required.
8. What is the scope of ISO 27001? Answer: ISO 27001 specifies the
requirements for establishing, implementing, maintaining, and continually
improving an ISMS within the context of the organization.
9. What is a security policy? Answer: A document that outlines an
organization's approach to information security, defining roles, responsibilities,
and the framework for managing security risks.

,10. What is risk assessment in the context of ISMS? Answer: The systematic
process of identifying, analyzing, and evaluating information security risks to
determine their potential impact on the organization.
11. What is risk treatment? Answer: The process of selecting and
implementing measures to modify, retain, avoid, or share information security
risks.
12. Name the four risk treatment options. Answer: Risk modification
(mitigation), Risk retention (acceptance), Risk avoidance, Risk sharing
(transfer)
13. What is the Statement of Applicability (SoA)? Answer: A documented
statement describing the control objectives and controls that are relevant and
applicable to the organization's ISMS.
14. How many control categories are there in ISO 27001:2022 Annex A?
Answer: 4 control categories (Organizational, People, Physical, Technological)
15. What is the total number of controls in ISO 27001:2022 Annex A?
Answer: 93 controls
16. What is the Plan-Do-Check-Act (PDCA) cycle? Answer: A continuous
improvement methodology where Plan (establish ISMS), Do (implement),
Check (monitor and review), Act (maintain and improve).
17. What is a control objective? Answer: A statement describing what is to be
achieved as a result of implementing controls.
18. What is an information security incident? Answer: A single or a series of
unwanted or unexpected information security events that have a significant
probability of compromising business operations.
19. What is vulnerability in information security? Answer: A weakness of an
asset or control that can be exploited by one or more threats.
20. What is a threat in information security? Answer: A potential cause of an
unwanted incident, which may result in harm to a system or organization.
21. What is an asset in the context of ISMS? Answer: Anything that has value
to the organization and therefore requires protection.
22. What are the main categories of assets? Answer: Primary assets (business
processes, activities, information) and Supporting assets (hardware, software,
network, personnel, site, organization structure)

, 23. What is business continuity? Answer: The capability of an organization to
continue delivery of products or services at acceptable predefined levels
following a disruptive incident.
24. What is disaster recovery? Answer: The process of regaining access and
functionality of IT infrastructure after events like natural disasters, cyber
attacks, or other disruptions.
25. What is the difference between corrective action and preventive action?
Answer: Corrective action addresses existing nonconformities, while preventive
action addresses potential nonconformities before they occur.
26. What is a nonconformity? Answer: Non-fulfillment of a requirement,
whether specified in the ISMS documentation or arising from legal/regulatory
obligations.
27. What is management review in ISMS? Answer: Top management's
formal evaluation of the ISMS to ensure its continuing suitability, adequacy,
effectiveness, and alignment with strategic direction.
28. What is internal audit in ISMS context? Answer: A systematic,
independent examination of the ISMS to determine whether it conforms to
planned arrangements and is effectively implemented and maintained.
29. What does "interested parties" mean in ISO 27001? Answer: Persons or
organizations that can affect, be affected by, or perceive themselves to be
affected by decisions or activities related to information security.
30. What is context of the organization? Answer: The combination of internal
and external issues that can influence an organization's approach to developing
and achieving its information security objectives.
31. What is information security risk? Answer: The potential that threats will
exploit vulnerabilities of an information asset and thereby cause harm to an
organization.
32. What is residual risk? Answer: The risk remaining after risk treatment
measures have been implemented.
33. What is acceptable risk? Answer: The level of risk that an organization is
willing to accept in pursuit of its objectives.
34. What is risk appetite? Answer: The amount and type of risk that an
organization is willing to pursue or retain.

Written for

Institution
IBITGQ - ISO CERTIFIED ISMS LEAD IMPLEMENTER
Course
IBITGQ - ISO CERTIFIED ISMS LEAD IMPLEMENTER

Document information

Uploaded on
June 18, 2025
Number of pages
27
Written in
2024/2025
Type
Exam (elaborations)
Contains
Unknown

Subjects

$50.99
Get access to the full document:

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF


Also available in package deal

Get to know the seller

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Mirror Liberty University
Follow You need to be logged in order to follow users or courses
Sold
425
Member since
3 year
Number of followers
137
Documents
4982
Last sold
1 week ago

3.8

59 reviews

5
23
4
18
3
9
2
4
1
5

Recently viewed by you

Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions