TÜV SÜD SOUTH ASIA
ISMS Lead Implementer Training Course
Pre-course Test
Ed 2022 Rev 1 – 20.12.2022
Name of Participant:
Name of Organization:
Date:
Write the answer to the following questions in the space provided:
1. Explain what you understand by Information Security Management System?
2. What are the benefits of implementing the requirements of ISO/IEC 27001:2022 standard
within an organization?
3. What is the difference between Correction and Corrective Action?. Explain in your own
words?
4. Define the following
a. Risk:
b. Asset:
c. Information security:
d. Security control:
e. Vulnerability:
Page 1 of 2
TÜV SÜD SOUTH ASIA
ISMS Lead Implementer Training Course
Pre-course Test
Ed 2022 Rev 1 – 20.12.2022
5. Explain what you understand by
a. Risk Identification:
b. Risk Analysis:
c. Risk Evaluation:
d. Risk Assessment:
6. Answer True or False. In case your answer is false, then you need to write the correct
statement.
a. ISO/IEC 27001:2022 is a product standard.
b. Asset Inventory needs to be maintained if one wants to implement ISMS.
c. An organization can get certified to ISO/IEC 27002.
d. Risk is also called vulnerability.
Note: Please bring this filled answer sheet with you on the first day of the course.
Page 2 of 2