ISO 28000:2007 is an ISO standard published by International Organization for Standardization which includes requirements of a security management system particularly dealing with security assurance in the supply chain. The standard was developed by ISO/TC 8 on "Ships and maritime technology" and published in 2007
Security management system for supply chain
Information security management system
Business continuity management system
Safety management systems
Rate this question:
Plan Do Correct Acknowledge
Plan Define Check Act
Plan Do Check Act
Please Do and Check Accordingly
Rate this question:
Any possible intentional action
Process of verifying the trustworthiness of people
Likelihood of a security threat materializing and the consequences
All of the above
Rate this question:
Always Every Year
At planned Intervals
Prior to Certification audit
As per management availability
Rate this question:
Physical failure threats and risks
Operational threats and risks
Stakeholder threats and risks
All of the above
Rate this question:
Security failure
Preventive action
Corrective action
Correction
Rate this question:
Identification of security threats
Determination of the risks associated with the identified security threats
Indication of the level of the risks related to each security threat and whether they are or are not, tolerable
All of the above.
Rate this question:
One or several corrective actions
One or several corrections
Corrective actions and preventive actions
None of the above
Rate this question:
Means by which a security management objective is achieved
Overall intentions and direction of an organization
Global security risks
Security achievements
Rate this question:
A competent internal auditor
Down stream Vendor
Upstream Vendor
All of the above
Rate this question:
Provide the framework which, enables the specific security management objectives, targets and programmes to be produced.
Be consistent with the organization’s overall security threat and risk management framework.
Include a commitment to continual improvement of the security management process.
Be documented, implemented and maintained;
All of the above
Rate this question:
Consistent with commitment to supplier evaluation ratings
One-time activity
Communicated to Regulatory body
Communicated, documented and reviewed periodically
Approved by Regulatory body
Rate this question:
Appointing a member of the top management with overall responsibility
Establish and maintain a structure of roles, responsibilities and authorities
Above two points
Companies to be certified to Information security
Rate this question:
Training and competence records
Security inspection reports
Reports of security exercises and drills
All of the above
Rate this question:
Trained auditors
Competent personnel
Certification body
None of the above.
Rate this question:
Quiz Review Timeline (Updated): Mar 21, 2023 +
Our quizzes are rigorously reviewed, monitored and continuously updated by our expert board to maintain accuracy, relevance, and timeliness.
Wait!
Here's an interesting quiz for you.