Free ISO 27001 Foundation Exam Flashcards

Memorize 50 essential terms and definitions for the PECB Certificate Holder in ISO/IEC 27001:2022 Foundation. See the term, recall the definition, then flip to check yourself.

50 Flashcards
11 Topics
100% Free
TermClick to flip

CIA Triad

Tap to reveal definition
Card 1 of 50CIA Triad & Security Properties

Filter by Topic

Jump to Card

About These ISO 27001 Foundation Flashcards

These 50 flashcards are designed to help you memorize key terms and definitions for the PECB Certificate Holder in ISO/IEC 27001:2022 Foundation. Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.

Topics Covered

CIA Triad & Security Properties6 cards
Risk & Security Concepts6 cards
ISO 27000 Standards Family8 cards
ISMS Fundamentals & PDCA3 cards
Cloud & AI Security2 cards
ISO 27001:2022 Structure (Clauses 4-10)7 cards
Risk Management Process6 cards
Annex A Controls & SoA6 cards
Leadership, Policy & Support3 cards
Performance Evaluation & Improvement2 cards
Security Control Types1 cards

Complete Flashcard Reference

Review every term in this set. Open any term to reveal its definition.

CIA Triad

Confidentiality, Integrity, and Availability are the three foundational information security properties used throughout PECB's Foundation materials. The exam tests each property individually and in combined scenarios.

Confidentiality (PECB terminology)

The property that information is not made available or disclosed to unauthorized individuals, entities, or processes. Enforced through access control, encryption, and need-to-know restrictions - distinct from integrity (accuracy) and availability (accessibility).

Integrity (PECB terminology)

The property of accuracy and completeness - information has not been altered or destroyed in an unauthorized manner. Hashing, digital signatures, and change/version control protect integrity.

Availability (PECB terminology)

The property of being accessible and usable on demand by an authorized entity. A published PECB sample question uses this exact wording - don't confuse it with confidentiality (who can see it) or integrity (is it accurate).

Authenticity vs. non-repudiation - what's the difference?

Authenticity is the property that an entity is what it claims to be, verified through authentication (passwords, tokens, certificates). Non-repudiation proves a claimed event occurred and stops the originator from denying it later, typically via digital signatures and audit logs.

Accountability vs. reliability - what's the difference?

Accountability ensures actions can be uniquely traced to the responsible entity, supported by authentication plus audit logging. Reliability is the property of consistent, intended behavior and results across systems and processes - a broader operational property.

Asset (PECB terminology)

Anything that has value to the organization and therefore needs protection. Assets are not just hardware - information itself, software, people, and services all qualify.

Threat (PECB terminology)

A potential cause of an unwanted incident that may result in harm to a system or organization. Threats can be deliberate (attackers), accidental (human error), or environmental (natural disaster) - they are the 'potential cause,' not the weakness itself.

Vulnerability (PECB terminology)

A weakness of an asset or control that can be exploited by one or more threats. Remember the chain: a threat exploits a vulnerability to affect an asset.

How do PECB Foundation materials define risk?

The effect of uncertainty on objectives, aligned with ISO 31000 - broader than the older 'threat x vulnerability x impact' shorthand some candidates expect. This effect is what an organization identifies, analyzes, and evaluates during risk assessment.

Impact (PECB terminology)

The adverse change to assets or to the organization caused by an information security incident. Impact is combined with likelihood during risk evaluation to determine the risk level.

Control (PECB terminology)

A measure that is modifying risk - a safeguard applied to reduce the likelihood or impact of a threat exploiting a vulnerability. Annex A of ISO/IEC 27001:2022 lists 93 reference controls an organization selects from.

What is ISO/IEC 27000's role in the standards family?

The current ISO/IEC 27000:2026 gives an overview of ISMS-family concepts, principles, and relationships. ISO/IEC 27001:2022 remains the requirements standard used for organizational certification.

ISO/IEC 27001 vs. ISO/IEC 27002 - what's the key difference?

27001 specifies the ISMS requirements an organization is certified against (Clauses 4-10 plus the Annex A control list). 27002 is a code of practice giving detailed implementation guidance for those controls and is NOT itself a certifiable standard.

What does ISO/IEC 27003 provide?

Guidance on implementing an ISMS - practical, step-by-step advice for meeting the ISO/IEC 27001 requirements. It complements 27002 (control guidance) and 27005 (risk guidance).

What does ISO/IEC 27004 provide?

Guidance on information security measurement - how to design and use metrics to evaluate ISMS and control effectiveness, directly supporting Clause 9.1 (monitoring, measurement, analysis, and evaluation).

What does ISO/IEC 27005 provide?

Guidance on information security risk management aligned with ISO/IEC 27001 - elaborating on risk identification, analysis, evaluation, treatment, and communication in more depth than Clause 6.1 alone.

ISO/IEC 27006 vs. ISO/IEC 27007 - what's the distinction?

27006 sets requirements that CERTIFICATION BODIES must meet to audit and certify ISMS, supplementing ISO/IEC 17021-1. 27007 gives guidelines for actually AUDITING an ISMS, applying ISO 19011's general audit principles to information security.

ISO/IEC 27017 vs. ISO/IEC 27018 - what's the distinction?

27017 provides cloud-specific security control guidance for both cloud providers and customers generally. 27018 is narrower - a code of practice specifically for protecting personally identifiable information (PII) in public clouds acting as PII processors.

What does ISO/IEC 27701 add to ISO/IEC 27001 and 27002?

It extends both standards with additional requirements and controls for managing privacy, establishing a Privacy Information Management System (PIMS) that supports GDPR and similar privacy regulations.

ISMS

Information Security Management System - a systematic, risk-based approach to managing sensitive information so it stays confidential, intact, and available. ISO/IEC 27001:2022 specifies the requirements an ISMS must meet.

PDCA cycle

Plan-Do-Check-Act - the iterative model for continual ISMS improvement. Plan sets objectives and processes, Do implements them, Check monitors and audits against the plan, and Act drives corrective and improvement action, closing the loop back to Plan.

What is a 'management system' under the ISO harmonized (Annex SL) structure?

A set of interrelated or interacting elements an organization uses to establish policies and objectives and the processes to achieve them. This shared high-level structure and terminology is why ISO/IEC 27001, ISO 9001, and ISO 14001 look so similar in outline.

Cloud shared-responsibility model: IaaS vs. SaaS

Under IaaS, the customer secures the guest OS, applications, and data while the provider secures the underlying infrastructure. Moving toward SaaS, the provider takes on more of the stack (platform and application), reducing - but never eliminating - the customer's data and access-management responsibilities.

What security risk is specific to AI systems?

AI systems can be vulnerable to adversarial inputs and training-data poisoning that undermine integrity and availability. Standard ISO/IEC 27001 controls (access control, secure development, data integrity) still apply, but the threat surface differs from traditional IT systems.

Which ISO/IEC 27001:2022 clauses hold the mandatory, auditable ISMS requirements?

Clauses 4 through 10. Clauses 1-3 (Scope, Normative references, Terms and definitions) are introductory only and are not themselves audited requirements.

Clause 4 - Context of the organization

Requires identifying internal and external issues and interested parties' requirements, then using that analysis to determine the ISMS scope (4.3) - the foundation all later planning builds on.

Clause 5 - Leadership

Requires top management to demonstrate leadership and commitment, establish the information security policy, and assign ISMS roles, responsibilities, and authorities.

Clause 6 - Planning

Covers addressing risks and opportunities plus risk assessment and treatment (6.1), setting measurable information security objectives (6.2), and planning changes to the ISMS (6.3).

Clause 7 - Support

Covers the enabling resources an ISMS needs to function: resources, competence, awareness, communication, and documented information.

Clause 8 - Operation

Covers operational planning and control - where the organization actually carries out the risk assessment and executes the risk treatment plan that Clause 6 required it to design.

Clause 9 - Performance Evaluation

Covers monitoring, measurement, analysis, and evaluation (9.1), internal audit (9.2), and management review (9.3) - the 'Check' activities that test whether the ISMS is actually working.

What are the three core steps of the risk assessment process?

Risk identification (finding risks to assets), risk analysis (understanding likelihood and consequences), and risk evaluation (comparing analyzed risk against acceptance criteria to prioritize treatment).

What is the purpose of risk treatment?

To select and apply options that bring risk within an acceptable level of residual risk - not to eliminate all risk, which is rarely possible or cost-effective.

Risk treatment: modify vs. share

Modify applies controls to reduce a risk's likelihood or impact (e.g., adding MFA). Share transfers all or part of the risk to a third party - commonly through insurance, outsourcing, or contracts - though accountability typically cannot be fully transferred.

Risk treatment: retain vs. avoid

Retain (accept) means taking no further action because residual risk is already below acceptance criteria. Avoid means a deliberate decision not to start, or to discontinue, the activity that creates the risk.

Risk owner

The person or entity with the accountability and authority to manage a specific risk, per Clause 6.1.2. Risk owners must approve both the risk treatment plan and acceptance of any residual risk.

Residual risk and the risk treatment plan

Residual risk is what remains after treatment has been applied and must be approved by the risk owner. The risk treatment plan documents the chosen options, the controls used to implement them (cross-referenced in the SoA), responsible owners, and timelines.

Annex A control count: 2022 vs. 2013

ISO/IEC 27001:2022 Annex A has 93 controls across 4 themes. The prior 2013 version had 114 controls across 14 categories - the 2022 revision consolidated duplicates and added 11 new controls.

Annex A's 4 themes, their control counts, and numbering

Organizational = 37 controls (A.5.x, the largest theme), People = 8 controls (A.6.x, the smallest), Physical = 14 controls (A.7.x), Technological = 34 controls (A.8.x). Numbering directly reflects the theme.

Statement of Applicability (SoA)

A mandatory document (Clause 6.1.3 d) that identifies the controls an organization has determined necessary, justifies including or excluding each one compared to Annex A, and states each control's implementation status.

Why is the SoA one of the most scrutinized documents in a certification audit?

Because it is the bridge between risk treatment and Annex A - it directly evidences which controls were chosen and why. Auditors verify the SoA reconciles with both the risk treatment plan and the actual controls in place.

Name the ISMS documents ISO/IEC 27001 explicitly requires as 'documented information.'

At minimum: ISMS scope, information security policy, risk assessment/treatment process and results, the SoA, security objectives, evidence of competence, and records of internal audits, management reviews, nonconformities, and corrective actions.

Can an organization exclude an Annex A control from its ISMS?

Yes - Annex A is a reference set, not a mandatory checklist. Controls may be excluded if justified in the SoA and if the exclusion does not undermine the organization's ability to meet its security requirements.

What must top management specifically do under Clause 5?

Under 5.1, demonstrate leadership and commitment (integrate ISMS into business processes, provide resources, communicate importance). Under 5.2, top management must personally establish and approve the information security policy - drafting can be delegated, approval cannot.

What type of policy is the ISO/IEC 27001 information security policy?

A high-level SPECIFIC policy - more focused than a general organization-wide business policy, but broader and more strategic than a topic-specific policy (like an access-control policy). This exact distinction appears in PECB's own published sample questions.

Competence (Clause 7.2) vs. awareness (Clause 7.3) - what's the difference?

Competence requires that people whose work affects the ISMS are qualified via education, training, or experience - with retained evidence. Awareness is broader: everyone under the organization's control must know the security policy, their contribution to the ISMS, and the consequences of not conforming.

Internal audit (9.2) vs. management review (9.3) - what's the difference?

Internal audit is an independent, objective check of whether the ISMS conforms to requirements and is effectively implemented. Management review is top management's own periodic assessment - using audit results as one input - of the ISMS's continuing suitability, adequacy, and effectiveness.

Nonconformity/corrective action (10.2) vs. continual improvement (10.1)

A nonconformity is the non-fulfillment of a requirement; Clause 10.2 requires reacting to it, eliminating its cause, and verifying the fix. Continual improvement (10.1) is the broader, ongoing enhancement of ISMS suitability, adequacy, and effectiveness - the 'Act' phase that closes PDCA.

Preventive vs. detective vs. corrective controls

Preventive controls act before an event to stop it (e.g., access control, MFA). Detective controls discover an event after it begins (e.g., a SIEM alert on failed logins). Corrective controls restore or limit damage after an incident (e.g., restoring from backup).

Frequently Asked Questions

What is the format of the PECB ISO/IEC 27001 Foundation exam?

Per PECB's official 2026 Candidate Handbook, the exam is 40 closed-book multiple-choice questions, each with 3 answer options, completed in 1 hour. The passing score is 70% (28 of 40 correct), and the exam mixes stand-alone questions with scenario-based questions.

How many domains does the exam cover, and how are they weighted?

PECB's official blueprint splits the exam into exactly 2 competency domains, each worth 50%: 'Fundamental principles and concepts of an ISMS' (20 questions) and 'Information security management system (ISMS)' (20 questions). Some marketing materials describe a more granular multi-topic breakdown, but the graded exam itself uses this 2-domain, 50/50 structure.

What happens if I fail the exam?

You must wait 15 days after your exam date before the first retake, and PECB places no cap on the total number of retakes. If you completed training through a PECB partner, your first retake is free within 12 months of course completion; standard retake fees apply after that.

Does the ISO 27001 Foundation certificate expire?

No. PECB's Certification Maintenance Policy explicitly exempts Foundation credentials (along with Provisional and Transition) from Continuing Professional Development submissions, the $120 Annual Maintenance Fee, and 3-year recertification - requirements that DO apply to Lead Implementer and Lead Auditor credentials.

How much does the exam cost?

PECB lists a $500 Foundation exam and $200 Foundation certificate application when purchased separately. For candidates completing required training through a PECB Partner, the training price includes the course, first exam attempt, first retake, and certificate application; partner prices vary.

What is the difference between ISO/IEC 27001 Foundation and the Lead Implementer/Lead Auditor credentials?

Foundation is PECB's entry-level certificate program with no professional-experience prerequisite; its required training and exam validate conceptual understanding of ISMS principles and ISO/IEC 27001:2022. Lead Implementer and Lead Auditor are practitioner-level credentials with longer exams and ongoing maintenance requirements.

Same family resources

Explore More PECB Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.