ISO Flashcards

(8 cards)

1
Q

What is the purpose of ISO 31000?

A

Provides principles and guidelines for managing risk across any organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the core principles of ISO 31000?

A

Create value; Be integrated and structured; Tailored to the organization; Continuous improvement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the purpose of ISO 27001?

A

Specifies requirements for an Information Security Management System (ISMS) to protect confidentiality, integrity, and availability. Cyber-Related

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the main approach used in ISO 27001?

A

Risk-based approach using the PDCA cycle and Annex A controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the purpose of ISO 22301?

A

Ensures organizations can continue operations during disruptive incidents through Business Continuity Management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are key components of ISO 22301?

A

Business Impact Analysis (BIA); Risk Assessment; Continuity Strategies; Testing & Exercises.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the purpose of ISO 27005?

A

Provides guidelines for managing information security risks, complementing ISO 27001. Cyber-Related

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the steps in ISO 27005 risk management?

A

Risk Identification; Risk Analysis; Risk Evaluation; Risk Treatment; Monitoring & Review.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly