Home » Articles posted by Helping Brainz Admin

Author Archives: Helping Brainz Admin

News/Events@HB

4th Masterclass by International TPRM Alliance

0%
3

4TPRMMasterclass

4th TPRM Masterclass

Please enter your full name, email address and location for certificate/score-generations! You will receive a certificate only if you score above 70%.

1 / 28

Category: 4TPRMMasterclass

1. The presentation identifies IP rights (A.5.32, Intellectual property rights) as particularly critical in agile outsourced engagements. What specific risk does it highlight that makes IP assignment more complex in this context?

2 / 28

Category: 4TPRMMasterclass

2. According to this presentation, what is the minimum set of security requirements the presentation recommends for ALL suppliers under A.5.20(Addressing information security within supplier agreements) implementation?

3 / 28

Category: 4TPRMMasterclass

3. A supplier relationship manager presents the following to an ISO 27001 auditor for A.5.19 (Information security in supplier relationships): a flat list of all active vendors with contract dates and the relevant account manager. The auditor raises a finding. What is the most accurate explanation for why this evidence is insufficient?

4 / 28

Category: 4TPRMMasterclass

4. In the TPRM operating model shown in this presentation, the 'Assess' step maps to specific ISO 27001 requirements and ISO 27002 implementation guidance. Which combination correctly describes both?

5 / 28

Category: 4TPRMMasterclass

5. According to the presentation, which of the following is a top nonconformity finding related to A.5.22 (Monitoring, review and change management of supplier services)?

6 / 28

Category: 4TPRMMasterclass

6. The presentation predicts that fourth-party assurance will become expected. What specific expansion of scope does it describe as the driver for this prediction?

7 / 28

Category: 4TPRMMasterclass

7. A.5.23 was introduced in ISO 27001:2022. What does this control cover?

8 / 28

Category: 4TPRMMasterclass

8. The presentation explains that ISO 27002 guidance items are not individually mandated and auditors must not raise nonconformities solely because an organisation chose a different implementation approach. However, there is an important limit to this principle. What is it?

9 / 28

Category: 4TPRMMasterclass

9. The presentation states that the Statement of Applicability (SOA) must reflect all applicable supplier controls — not just the core four. How many primary supplier controls are listed in this presentation?

10 / 28

Category: 4TPRMMasterclass

10. The presentation distinguishes ISO 27002 from ISO 27001 in a specific and important way. Which statement accurately captures that distinction?

11 / 28

Category: 4TPRMMasterclass

11. According to this presentation, when an organisation excludes a requirement from Clauses 4–10 of ISO 27001, how is this treated?

12 / 28

Category: 4TPRMMasterclass

Which topics would you like to see covered in future roundtables or masterclasses?
e.g.,

  • 12. Third-Party Cyber Risk & Continuous Monitoring
  • AI Risk in Vendor Ecosystems
  • Cloud & SaaS Risk Management
  • Regulatory Compliance (e.g., outsourcing, data protection)
  • Fourth-Party / Concentration Risk
  • Incident & Breach Management involving vendors
  • Other (please specify): __________

13 / 28

Category: 4TPRMMasterclass

13. For A.8.30(Outsourced development), the presentation specifies three operative verbs that describe the organisation's obligations toward outsourced development. Which set is correct?

14 / 28

Category: 4TPRMMasterclass

14. Please share your feedback on the event

  • What did you find most valuable?
  • What could be improved?
  • Any suggestions for future sessions?

15 / 28

Category: 4TPRMMasterclass

15. According to this presentation, what percentage of significant data breaches involve a third party?

16 / 28

Category: 4TPRMMasterclass

16. Under A.5.20(Addressing information security within supplier agreements), the presentation warns that a particular approach does NOT satisfy the 'established and agreed' requirement. Which approach is explicitly flagged as insufficient for high-risk suppliers?

17 / 28

Category: 4TPRMMasterclass

17. According to this presentation, how is A.8.30 (Outsourced Development) treated in the Statement of Applicability, and what determines its applicability?

18 / 28

Category: 4TPRMMasterclass

18. what does it mean for a control to be 'declared applicable in the SOA with no operational evidence'?

19 / 28

Category: 4TPRMMasterclass

19. For A.5.22(Monitoring, review and change management of supplier services), the presentation identifies three distinct obligations within the single control. What are they?

20 / 28

Category: 4TPRMMasterclass

20. A software company outsources the development of its mobile banking application to a third-party development firm. The firm delivers code bi-weekly via an agile sprint process. Under A.8.30 (Outsourced development
Control), which combination of actions does the presentation indicate the organisation must demonstrate?

21 / 28

Category: 4TPRMMasterclass

How would you rate the overall experience of the event?

  • 21. Highly insightful and engaging
  • Informative and valuable
  • Average / satisfactory
  • Lengthy but useful
  • Too long and less engaging
  • Not relevant / could be improved

22 / 28

Category: 4TPRMMasterclass

22. For control A.5.19(Information security in supplier relationships), the presentation specifies what auditors look for as evidence. Which of the following correctly reflects that evidence requirement?

23 / 28

Category: 4TPRMMasterclass

23. What are the four lifecycle stages explicitly named in the A.5.23 requirement for cloud services?

24 / 28

Category: 4TPRMMasterclass

24. Which clause of ISO 27001 explicitly requires that 'externally provided processes, products or services that are relevant to the ISMS are controlled'?

25 / 28

Category: 4TPRMMasterclass

25. The presentation explains that A.5.21(Managing information security in the information and communication technology (ICT) supply chain) extends beyond direct suppliers. What does it explicitly include in scope?

26 / 28

Category: 4TPRMMasterclass

26. According to the presentation, what is the TPRM operating model's five-step sequence?

27 / 28

Category: 4TPRMMasterclass

27. An organisation's A.5.23 process consists entirely of a SaaS vendor questionnaire completed at onboarding. The auditor notes a gap. Based on the presentation, which specific element of A.5.23(Information security for use of cloud services) is most clearly missing?

28 / 28

Category: 4TPRMMasterclass

28. An organisation uses a single standard NDA for all suppliers — from a one-person consultancy to a SaaS provider processing thousands of customer records. Under A.5.20 (Addressing information security within supplier agreements), why does the presentation indicate this approach creates a control gap for high-risk suppliers?

Your score is

0%

Exit

18th TPRM Roundtable by International TPRM Alliance

0%
13

The quiz has expired!

Protected: DIN

This content is password-protected. To view it, please enter the password below.

21st National Cyber Security and Cyber Crime Awareness Session at Reliance Industries Limited, Surat

Helping Brainz’s Cybersecurity and Legal Awareness Team shall be conducting their 21st National Cybersecurity and Cybercrime Awareness Session at Reliance Industries, Surat.

Helping Brainz is gearing up to organize a crucial Cyber Security and Cyber Crime Awareness Session that promises to be an invaluable resource for the community. With the digital landscape becoming increasingly complex, this session aims to educate individuals on how to safeguard themselves against cyber threats.

0%
19

You have 10 mins to complete this QUIZ! Wish you all the best!

Time is UP!


Cyber Security General Awareness

21st National Cyber Security and Cyber Crime Awareness Session at Reliance Industries Limited, Surat

 

Please enter your full name and email address  for certificate/score-generations! You will receive only if you score above 70%.

1 / 20

Category: Cyber Security General Awareness

1. You receive a phone call from the bank that particular person is asking you for your account details for a vertification. Unfortunately, you give your details and your money and has been withdrawn. You have been victim of which cyber attack?

2 / 20

Category: Cyber Security General Awareness

2. Select the fullform of "DDoS"

3 / 20

Category: Cyber Security General Awareness

3. Which portal is used to report a cyber crime in India ?

4 / 20

Category: Cyber Security General Awareness

4. Is the following statement true or false? Reusing the same password across multiple sites is a good idea. It's very convenient after all.

5 / 20

Category: Cyber Security General Awareness

5. You receive a text message from an unknown number. The text says that if you click the link provided, it will redirect you to a site where you can watch the latest award-winning movie that is still in theatres. You see that the link referenced is from a popular URL shortening site. You should:

6 / 20

Category: Cyber Security General Awareness

6. Which of the following best describes a grandparent scam?

7 / 20

Category: Cyber Security General Awareness

7. Which of the following would be the best password (hardest to crack)?

8 / 20

Category: Cyber Security General Awareness

8. You fell victim to a scam, through which an attacker stole money from you. What should you do?

9 / 20

Category: Cyber Security General Awareness

9. What is the meaning of Encryption?

10 / 20

Category: Cyber Security General Awareness

10. Which computer virus records every movement you make on your computer?

11 / 20

Category: Cyber Security General Awareness

11. What is a person called when they try to hurt a group of people with the use of a computer?

12 / 20

Category: Cyber Security General Awareness

12. Is it generally considered safe to use Starbucks Public Wi-Fi network for performing an online banking operation?

13 / 20

Category: Cyber Security General Awareness

13. Which of the following should you NOT publish on social media sites?

14 / 20

Category: Cyber Security General Awareness

14. Is the following statement true or false. Because operating system updates are time consuming and may need to restart the machine it's a good idea to postpone them as long as possible.

15 / 20

Category: Cyber Security General Awareness

15. Mary downloaded a free software program from an unknown website. After installing the program, her computer started behaving strangely and her files were encrypted. What likely happened, and what should Mary do?

16 / 20

Category: Cyber Security General Awareness

16. Rahul sees an advertisement promising immediate job placements in reputable companies without requiring any prior qualifications. All he needs to do is provide his personal information. What should Rahul do?

17 / 20

Category: Cyber Security General Awareness

17. How was the event ?

(a) Interesting

(b) Boring

(c) Informative

(d) Lengthy

Please mention the option in the answer-box below

18 / 20

Category: Cyber Security General Awareness

Will you try sharing whatever you learnt today with your friends, relatives and neighbours ?

18. (We will be also interested to conduct an event in your friend's school or college, so that they are also cyber secure. If you are interested to nominate a school or a college, please email us at help@helpingbrainz.org or call us at 8921979187) 

An opportunity for you to give back to the community!

(Note: This question doesn't have a score)

19 / 20

Category: Cyber Security General Awareness

19. When visiting a website, you notice a lock 🔒 icon next to the web address. What does the lock 🔒 represent?

20 / 20

Category: 5th TPRM Roundtable 2024

20. Your esteemed feedback about the event ?

 

Your score is

0%

Protected: CyberAwareness

This content is password-protected. To view it, please enter the password below.

Privacy Practice

Wrong shortcode initialized

PrivacyAwareness2022

Wrong shortcode initialized