ISO-IEC-27001-LEAD-AUDITOR · Question #143
Drag and Drop Question Select the correct sequence for the information security risk assessment process in an ISMS. To complete the sequence click on the blank section you want to complete so that…
The correct answer is Establish information security criteria; Identify the information security risks; Analyse the information security risks; Treat the information security risks. ISO/IEC 27001 - Risk Assessment Process Sequence This question is based on ISO/IEC 27001, which defines the mandatory steps for risk assessment within an Information Security Management System (ISMS), primarily in Clause 6.1.2 (risk assessment) and Clause 6.1.3 (risk…
Question
Drag and Drop Question Select the correct sequence for the information security risk assessment process in an ISMS. To complete the sequence click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the options to the appropriate blank Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- Establish information security criteria
- Identify the information security risks
- Analyse the information security risks
- Treat the information security risks
Explanation
ISO/IEC 27001 - Risk Assessment Process Sequence
This question is based on ISO/IEC 27001, which defines the mandatory steps for risk assessment within an Information Security Management System (ISMS), primarily in Clause 6.1.2 (risk assessment) and Clause 6.1.3 (risk treatment).
Why This Order?
The logic is linear and causal: you cannot assess what you haven't defined, you cannot treat what you haven't identified, and you cannot treat before you analyse. Each step gates the next.
Step-by-Step Breakdown
1. Establish information security criteria
You must define the rules of the game before playing. This includes:
- Risk acceptance criteria (what level of risk is tolerable?)
- Criteria for performing the risk assessment (scope, methodology, severity scales)
Without this foundation, risk identification and analysis have no consistent reference point. Nothing else can proceed meaningfully.
Distractor - "Determine information security criteria": "Determine" implies discovering criteria that already exist externally. ISO 27001 uses "establish" because the organization actively creates these criteria. This is a deliberate word-choice trap.
2. Identify the information security risks
With criteria in place, you now systematically find what could go wrong - mapping threats and vulnerabilities to assets, and naming risk owners. You cannot analyse a risk you haven't named.
3. Analyse the information security risks
For each identified risk, you assess:
- Likelihood of occurrence
- Consequence (impact on confidentiality, integrity, availability)
- Risk level (combining the two)
This quantifies or qualifies the risk so decisions can be made.
Distractor - "Evaluate the information security risks": This is a genuine ISO 27001 sub-step (Clause 6.1.2e) that compares analysed risks against the criteria from Step 1 to prioritise them. Many exam questions include it as a distinct step. Here, the exam collapses analyse + evaluate or treats it as implicit within "analyse." If your exam or course separates them, the full order would be: establish → identify → analyse → evaluate → treat.
4. Treat the information security risks
Only after risks are identified and analysed can the organization decide how to respond - mitigate, accept, avoid, or transfer. Defined in Clause 6.1.3, this step produces the Statement of Applicability (SoA) and risk treatment plan.
Common Mistakes & Misconceptions
| Mistake | Clarification |
|---|---|
| Putting "treat" before "analyse" | You cannot decide on a treatment without knowing the risk level |
| Choosing "Determine" over "Establish" | ISO 27001 explicitly uses "establish" - the org creates the criteria |
| Omitting criteria as the first step | Many assume you start with identification; criteria must come first to make identification meaningful |
| Treating "evaluate" and "analyse" as identical | ISO 27001 separates them; "analyse" = calculate risk levels, "evaluate" = compare to criteria and prioritise |
Bottom line: The sequence follows a strict logical dependency chain - you define, then discover, then understand, then act. Each step is prerequisite to the next.
Topics
Community Discussion
No community discussion yet for this question.
