Highlights
Questions
The first step towards the implementation of an ISMS (Information Security Management System) in an organisation is to define its boundaries to define the ISMS scope.
Discuss two advantages of defining an ISMS scope.
Discuss two relevant things that should be considered when defining an ISMS scope. Your discussion should be related to the XYZ-VISA scenario in the Appendix.
Explain two differences between the in-scope and out-of-scope area. You should use examples related to the XYZ-VISA scenario in the Appendix in your explanation.
Explain one drawback and one advantage of narrow ISMS scope.
Provide and justify two in-scope and two out-of-scope elements from the scenario in Appendix A.
One of the most important steps during risk assessment is evaluating the assets in the organization.
Critically discuss three differences between primary and secondary assets?
List and justify two primary and three secondary assets from the scenario in Appendix A.
List the two steps of risk assessment under ISO 27005, and explain each step using the XYZ-VISA scenario.
List the two steps of risk assessment under NIST SP800-30, and explain each step using the XYZ-VISA scenario.
Critically discuss two differences between ISO 27005 and NIST SP800-30
Explain each of three phases of the PDCA (Plan-Do-Check-Act) process prescribed by the ISO 27001 standard for information security management.
Consider the XYZ-VISA scenario in Appendix A. Describe one example of activities performed in each of the 5 generic phases of risk assessment preparation risk identification risk analysis risk evaluation and risk treatment. Your examples have to be related to the given scenario.
This IT and Computer Science has been solved by our PHD Experts at My Uni Paper.
© Copyright 2026 My Uni Papers – Student Hustle Made Hassle Free. All rights reserved.