nerdexam
EXIN

ISFS · Question #87

Which of the following is a best practice concerning Information Security Risk assessment?

The correct answer is C. Information Security Risk assessments should be performed at agreed intervals and be maintained. Option C reflects the guidance in ISO/IEC 27001, which requires risk assessments to be conducted at planned (agreed) intervals and whenever significant changes occur - and crucially, that results be documented and maintained over time, enabling trend analysis and audit…

Risk and security management

Question

Which of the following is a best practice concerning Information Security Risk assessment?

Options

  • AInformation Security Risk assessments should be carried out by an external auditor to
  • BInformation Security Risk assessments should be performed as a result of the review of every
  • CInformation Security Risk assessments should be performed at agreed intervals and be maintained
  • DInformation Security Risk assessments should be performed once a year.

How the community answered

(28 responses)
  • A
    4% (1)
  • C
    89% (25)
  • D
    7% (2)

Explanation

Option C reflects the guidance in ISO/IEC 27001, which requires risk assessments to be conducted at planned (agreed) intervals and whenever significant changes occur - and crucially, that results be documented and maintained over time, enabling trend analysis and audit evidence. This flexible, ongoing approach is the recognized best practice.

Why the others are wrong:

  • A is incorrect because risk assessments can and often should be conducted internally; there is no requirement for an external auditor to perform them (though external auditors may review them).
  • B is incorrect because performing a full risk assessment after every review would be impractical and is not required - assessments are triggered by agreed intervals or significant changes, not every routine review.
  • D is incorrect because locking to a fixed annual schedule is too rigid; organizational changes, new threats, or system updates may demand assessments more frequently, and the standard intentionally leaves the interval flexible ("agreed" by the organization).

Memory tip: Think of the phrase "agreed and maintained" - risk management is a living process, not a one-time event or an outsourced checkbox. If an answer implies rigid frequency or mandatory external involvement, it's almost certainly wrong.

Topics

#risk assessment#best practice#agreed intervals#ISO 27001

Community Discussion

No community discussion yet for this question.

Full ISFS Practice