How is an "information need' typically defined in the context of ISMS monitoring?
Correct Answer: C
In the context of ISMS monitoring, an "information need" is typically defined as a high-level security question or statement that management wants answered to support decision-making. It frames what information is required and why, rather than specifying how it will be technically measured. ISO/IEC 27001:2022 Clause 9.1 - Monitoring, measurement, analysis and evaluation requires organizations to determine: * what needs to be monitored and measured, * methods for monitoring and measurement, * when monitoring and measurement shall be performed, * and when results shall be analyzed and evaluated. An information need precedes metrics and indicators. Examples include: * "Are access controls preventing unauthorized access?" * "Is incident response timely and effective?" These are high-level questions, not technical specifications (Option A) and not predefined control lists (Option B). Metrics, dashboards, and KPIs are derived after the information need is defined. This approach ensures that monitoring remains business-relevant and risk-focused, aligning measurement with objectives and management review requirements.
Question 152
Which tool is used to identify, analyze, and manage interested parties?
Correct Answer: B
The power/interest matrix is a tool that can be used to identify, analyze, and manage interested parties according to ISO/IEC 27001:2022. The power/interest matrix is a two-dimensional diagram that plots the level of power and interest of each interested party in relation to the organization's information security objectives. The power/interest matrix can help the organization to prioritize the interested parties, understand their expectations and needs, and develop appropriate communication and engagement strategies. The power/interest matrix can also help the organization to identify potential risks and opportunities related to the interested parties. References: ISO/IEC 27001:2022, clause 4.2; PECB ISO/IEC 27001 Lead Implementer Course, Module 4, slide 12.
Question 153
Which approach should organizations use to implement an ISMS based on ISO/IEC 27001?
Correct Answer: C
Question 154
An organization that has an ISMS in place conducts management reviews at planned intervals, but does not retain documented information on the results. Is this in accordance with the requirements of ISO/IEC 27001?
Correct Answer: B
According to ISO/IEC 27001:2022, clause 9.3.3, the organization must retain documented information as evidence of the results of management reviews. The results of management reviews must include decisions and actions related to the ISMS policy, objectives, risks, opportunities, resources, and communication. Documenting the results of management reviews is important to ensure the accountability, traceability, and effectiveness of the ISMS. It also helps the organization to monitor and measure the performance and improvement of the ISMS, and to demonstrate compliance with the requirements of ISO/IEC 27001:2022. Therefore, an organization that has an ISMS in place and conducts management reviews at planned intervals, but does not retain documented information on the results, is not in accordance with the requirements of ISO/IEC 27001. (From the PECB ISO/IEC 27001 Lead Implementer Course Manual, page 107) References: * PECB ISO/IEC 27001 Lead Implementer Course Manual, page 107 * PECB ISO/IEC 27001 Lead Implementer Info Kit, page 7 * ISO/IEC 27001:2022 (en), Information security, cybersecurity and privacy protection - Information security management systems - Requirements, clause 9.3.3 1
Question 155
Company X restricted the access of the internal auditor of some of its documentation taking into account its confidentiality. Is this acceptable?