ISFS · Question #87
Which of the following is a best practice concerning Information Security Risk assessment?
The correct answer is C. Information Security Risk assessments should be performed at agreed intervals and be maintained. Option C reflects the guidance in ISO/IEC 27001, which requires risk assessments to be conducted at planned (agreed) intervals and whenever significant changes occur - and crucially, that results be documented and maintained over time, enabling trend analysis and audit…
Question
Which of the following is a best practice concerning Information Security Risk assessment?
Options
- AInformation Security Risk assessments should be carried out by an external auditor to
- BInformation Security Risk assessments should be performed as a result of the review of every
- CInformation Security Risk assessments should be performed at agreed intervals and be maintained
- DInformation Security Risk assessments should be performed once a year.
How the community answered
(28 responses)- A4% (1)
- C89% (25)
- D7% (2)
Explanation
Option C reflects the guidance in ISO/IEC 27001, which requires risk assessments to be conducted at planned (agreed) intervals and whenever significant changes occur - and crucially, that results be documented and maintained over time, enabling trend analysis and audit evidence. This flexible, ongoing approach is the recognized best practice.
Why the others are wrong:
- A is incorrect because risk assessments can and often should be conducted internally; there is no requirement for an external auditor to perform them (though external auditors may review them).
- B is incorrect because performing a full risk assessment after every review would be impractical and is not required - assessments are triggered by agreed intervals or significant changes, not every routine review.
- D is incorrect because locking to a fixed annual schedule is too rigid; organizational changes, new threats, or system updates may demand assessments more frequently, and the standard intentionally leaves the interval flexible ("agreed" by the organization).
Memory tip: Think of the phrase "agreed and maintained" - risk management is a living process, not a one-time event or an outsourced checkbox. If an answer implies rigid frequency or mandatory external involvement, it's almost certainly wrong.
Topics
Community Discussion
No community discussion yet for this question.