ISO-IEC-27001-LEAD-AUDITOR · Question #134
You are an experienced ISMS audit team leader conducting a third-party surveillance audit of an internet services provider. You are reviewing the organization's risk assessment processes for…
The correct answer is B. The organisation is treating information security risks in the order in which they are identified E. The organisation's risk assessment criteria have not been reviewed and approved by top F. The organisation's information security risk assessment process is based solely on an. The three audit findings that would prompt you to raise a nonconformity report are: The organisation is treating information security risks in the order in which they are identified The organisation's risk assessment criteria have not been reviewed and approved by top The…
Question
You are an experienced ISMS audit team leader conducting a third-party surveillance audit of an internet services provider. You are reviewing the organization's risk assessment processes for conformity with ISO/IEC 27001:2022. Which three of the following audit findings would prompt you to raise a nonconformity report?
Options
- ABoth systems contain additional information security risks which are not associated with
- BThe organisation is treating information security risks in the order in which they are identified
- CThe organisation's information security risk assessment process suggests each risk is allocated a
- DThe organisation has not used RAG (Red, Amber, Green) to classify its' information security risks.
- EThe organisation's risk assessment criteria have not been reviewed and approved by top
- FThe organisation's information security risk assessment process is based solely on an
- GThe organisation has assessed the probability of all of its information security risks as either 0%,
- HThere is a different system in place for assessing operational information security risks and for
How the community answered
(58 responses)- A9% (5)
- B64% (37)
- C19% (11)
- D2% (1)
- G5% (3)
- H2% (1)
Explanation
The three audit findings that would prompt you to raise a nonconformity report are: The organisation is treating information security risks in the order in which they are identified The organisation's risk assessment criteria have not been reviewed and approved by top The organisation's information security risk assessment process is based solely on an assessment of the impact of each risk According to ISO/IEC 27001:2022, clause 6.1.2, the organisation must establish and maintain an information security risk management process that is consistent with the organisation's context and aligned with its overall risk management approach1. This process must include the following Establishing the risk assessment criteria, which must be approved by top management and reflect the organisation's risk appetite and objectives2 Identifying the information security risks, which must consider the assets, threats, vulnerabilities, impacts, and likelihoods3 Analysing the information security risks, which must determine the levels of risk and compare them with the risk criteria4 Evaluating the information security risks, which must prioritise the risks and decide whether they need treatment or not5
Topics
Community Discussion
No community discussion yet for this question.