ISO 27001 Information Security Management Vocabulary
Practice the key concepts and vocabulary of the ISO 27001 information security standard.
0 / 13 completed
1 / 13
What is an ISMS in the context of ISO 27001?
The ISMS is the core concept of ISO 27001: a systematic approach to managing sensitive information so it remains secure.
2 / 13
What is a Statement of Applicability (SoA) in ISO 27001?
The SoA is a mandatory ISO 27001 document that justifies which controls are included or excluded from the ISMS scope.
3 / 13
An auditor asks about your risk treatment plan. What does this document describe?
ISO 27001 risk treatment plans document the decision made for each identified risk and the controls selected to address risks that are mitigated.
4 / 13
What is the difference between a vulnerability and a threat in information security?
ISO 27005 risk assessment: threat x vulnerability x impact = risk. An unpatched system is a vulnerability; a malicious actor is a threat.
5 / 13
A colleague says we need to do a management review. What does this mean in ISO 27001 context?
Management reviews (Clause 9.3) are mandatory ISO 27001 reviews that ensure top management remains engaged with ISMS effectiveness.
6 / 13
During a code review of the new API endpoint for user profile updates, David raises concerns about data sensitivity. He asks if we've formally assessed and documented the risks associated with unauthorized access to this data, referencing our ISO 27001 obligations. Specifically, he wants to know how we're demonstrating that we've addressed potential vulnerabilities related to data leakage or modification.
Which of the following documents would best fulfill this requirement?
The correct answer is (B). An SoA is *the* key document for demonstrating ISO 27001 compliance. It's a critical mapping exercise that explicitly links identified risks to chosen controls. Options A and C are related but don't represent the core requirement of documenting risk assessment and control selection. Option D provides operational metrics, not evidence of risk mitigation strategy.
7 / 13
During a code review of the new customer onboarding service, Emily notes that we're collecting personally identifiable information (PII) from users. She asks if we've formally documented our approach to managing this PII according to ISO 27001 standards, specifically addressing potential risks related to data breaches or unauthorized disclosure. A key concern is ensuring compliance with GDPR requirements alongside the ISMS framework. Which of the following documents would best demonstrate this compliance?
The correct answer is (B). An SoA is crucial for demonstrating ISO 27001 compliance as it maps identified risks to selected controls. It's essential to document PII handling procedures, including data protection measures and incident response plans – aligning with the ISMS framework and GDPR requirements. Options A, C, and D focus on technical details or unrelated aspects of security, not the overall risk management process required by ISO 27001.
8 / 13
During a code review of the new API endpoint for user profile updates, David raises concerns about data sensitivity. He asks if we've formally assessed and documented the risks associated with unauthorized access to this data, referencing our ISO 27001 obligations. Specifically, he wants to know how we're demonstrating that we've addressed potential vulnerabilities related to data leakage or modification.
Which of the following documents would best fulfill this requirement?
The correct answer is (B). An SoA is *the* key document for demonstrating ISO 27001 compliance. It's a critical mapping exercise that explicitly links identified risks to chosen controls. Options A and C are related but don't represent the core requirement of documenting risk assessment and control selection. Option D provides operational metrics, not evidence of risk mitigation strategy.
9 / 13
During a code review of the new customer onboarding service, Emily notes that we're collecting personally identifiable information (PII) from users. She asks if we've formally documented our approach to managing this PII according to ISO 27001 standards, specifically addressing potential risks related to data breaches or unauthorized disclosure. A key concern is ensuring compliance with GDPR requirements alongside the ISMS framework. Which of the following documents would best demonstrate this compliance?
The correct answer is (B). An SoA is crucial for demonstrating ISO 27001 compliance as it maps identified risks to selected controls. It's essential to document PII handling procedures, including data protection measures and incident response plans – aligning with the ISMS framework and GDPR requirements. Options A, C, and D focus on technical details or unrelated aspects of security, not the overall risk management process required by ISO 27001.
10 / 13
During a code review of the new API endpoint for user profile updates, David raises concerns about data sensitivity. He asks if we've formally assessed and documented the risks associated with unauthorized access to this data, referencing our ISO 27001 obligations. Specifically, he wants to know how we're demonstrating that we've addressed potential vulnerabilities related to data leakage or modification.
Which of the following documents would best fulfill this requirement?
The correct answer is (B). An SoA is *the* key document for demonstrating ISO 27001 compliance. It's a critical mapping exercise that explicitly links identified risks to chosen controls. Options A and C are related but don't represent the core requirement of documenting risk assessment and control selection. Option D provides operational metrics, not evidence of risk mitigation strategy.
11 / 13
During a code review of the new customer onboarding service, Emily notes that we're collecting personally identifiable information (PII) from users. She asks if we've formally documented our approach to managing this PII according to ISO 27001 standards, specifically addressing potential risks related to data breaches or unauthorized disclosure. A key concern is ensuring compliance with GDPR requirements alongside the ISMS framework. Which of the following documents would best demonstrate this compliance?
The correct answer is (B). An SoA is crucial for demonstrating ISO 27001 compliance as it maps identified risks to selected controls. It's essential to document PII handling procedures, including data protection measures and incident response plans – aligning with the ISMS framework and GDPR requirements. Options A, C, and D focus on technical details or unrelated aspects of security, not the overall risk management process required by ISO 27001.
12 / 13
During a code review of the new API endpoint for user profile updates, David raises concerns about data sensitivity. He asks if we've formally assessed and documented the risks associated with unauthorized access to this data, referencing our ISO 27001 obligations. Specifically, he wants to know how we're demonstrating that we've addressed potential vulnerabilities related to data leakage or modification.
Which of the following documents would best fulfill this requirement?
The correct answer is (B). An SoA is *the* key document for demonstrating ISO 27001 compliance. It's a critical mapping exercise that explicitly links identified risks to chosen controls. Options A and C are related but don't represent the core requirement of documenting risk assessment and control selection. Option D provides operational metrics, not evidence of risk mitigation strategy.
13 / 13
During a code review of the new customer onboarding service, Emily notes that we're collecting personally identifiable information (PII) from users. She asks if we've formally documented our approach to managing this PII according to ISO 27001 standards, specifically addressing potential risks related to data breaches or unauthorized disclosure. A key concern is ensuring compliance with GDPR requirements alongside the ISMS framework. Which of the following documents would best demonstrate this compliance?
The correct answer is (B). An SoA is crucial for demonstrating ISO 27001 compliance as it maps identified risks to selected controls. It's essential to document PII handling procedures, including data protection measures and incident response plans – aligning with the ISMS framework and GDPR requirements. Options A, C, and D focus on technical details or unrelated aspects of security, not the overall risk management process required by ISO 27001.
What does the "ISO 27001 Information Security Management Vocabulary" exercise practise?
Practice the key concepts and vocabulary of the ISO 27001 information security standard.
How many questions are in this exercise?
This exercise has 13 questions, each multiple-choice with a full explanation shown after you answer.
What English level is this exercise for?
This exercise is tagged Intermediate. If the vocabulary feels difficult, browse the Compliance Security category page for an easier module to start with.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free with no account, sign-up, or paywall.
Do I get feedback if I answer incorrectly?
Yes — whichever option you choose, right or wrong, you'll immediately see an explanation clarifying the correct term and why the other options don't fit.
Can I retry this exercise?
Yes — once you finish all the questions, a "Try again" button on the results screen resets the exercise so you can practise as many times as you like.
Do I need an account to track my progress?
No account is required. Your progress bar and score for this session are tracked in the browser as you go, but nothing is saved once you leave the page.
Is "ISO 27001 Information Security Management Vocabulary" part of a larger series?
Yes — it's one exercise in the Compliance Security category on CoderSlingo. See the category page for the full list of related exercises on similar terminology.
Can I link directly to this exercise?
Yes — this exercise has its own permanent URL, so you can bookmark it or share the link directly with a colleague or study partner.
Where can I find more exercises like this one?
See the Compliance Security category page for related exercises, or browse the main Exercises hub for other IT English topics.