nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #143

Drag and Drop Question Select the correct sequence for the information security risk assessment process in an ISMS. To complete the sequence click on the blank section you want to complete so that…

The correct answer is Establish information security criteria; Identify the information security risks; Analyse the information security risks; Treat the information security risks. ISO/IEC 27001 - Risk Assessment Process Sequence This question is based on ISO/IEC 27001, which defines the mandatory steps for risk assessment within an Information Security Management System (ISMS), primarily in Clause 6.1.2 (risk assessment) and Clause 6.1.3 (risk…

Information Security Risk Management

Question

Drag and Drop Question Select the correct sequence for the information security risk assessment process in an ISMS. To complete the sequence click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the options to the appropriate blank Answer:

Exhibit

ISO-IEC-27001-LEAD-AUDITOR question #143 exhibit

Answer Area

Drag items

Identify the information security risksEvaluate the information security risksEstablish information security criteriaDetermine information security criteriaAnalyse the information security risksTreat the information security risks

Correct arrangement

  • Establish information security criteria
  • Identify the information security risks
  • Analyse the information security risks
  • Treat the information security risks

Explanation

ISO/IEC 27001 - Risk Assessment Process Sequence

This question is based on ISO/IEC 27001, which defines the mandatory steps for risk assessment within an Information Security Management System (ISMS), primarily in Clause 6.1.2 (risk assessment) and Clause 6.1.3 (risk treatment).


Why This Order?

The logic is linear and causal: you cannot assess what you haven't defined, you cannot treat what you haven't identified, and you cannot treat before you analyse. Each step gates the next.


Step-by-Step Breakdown

1. Establish information security criteria

You must define the rules of the game before playing. This includes:

  • Risk acceptance criteria (what level of risk is tolerable?)
  • Criteria for performing the risk assessment (scope, methodology, severity scales)

Without this foundation, risk identification and analysis have no consistent reference point. Nothing else can proceed meaningfully.

Distractor - "Determine information security criteria": "Determine" implies discovering criteria that already exist externally. ISO 27001 uses "establish" because the organization actively creates these criteria. This is a deliberate word-choice trap.


2. Identify the information security risks

With criteria in place, you now systematically find what could go wrong - mapping threats and vulnerabilities to assets, and naming risk owners. You cannot analyse a risk you haven't named.


3. Analyse the information security risks

For each identified risk, you assess:

  • Likelihood of occurrence
  • Consequence (impact on confidentiality, integrity, availability)
  • Risk level (combining the two)

This quantifies or qualifies the risk so decisions can be made.

Distractor - "Evaluate the information security risks": This is a genuine ISO 27001 sub-step (Clause 6.1.2e) that compares analysed risks against the criteria from Step 1 to prioritise them. Many exam questions include it as a distinct step. Here, the exam collapses analyse + evaluate or treats it as implicit within "analyse." If your exam or course separates them, the full order would be: establish → identify → analyse → evaluate → treat.


4. Treat the information security risks

Only after risks are identified and analysed can the organization decide how to respond - mitigate, accept, avoid, or transfer. Defined in Clause 6.1.3, this step produces the Statement of Applicability (SoA) and risk treatment plan.


Common Mistakes & Misconceptions

MistakeClarification
Putting "treat" before "analyse"You cannot decide on a treatment without knowing the risk level
Choosing "Determine" over "Establish"ISO 27001 explicitly uses "establish" - the org creates the criteria
Omitting criteria as the first stepMany assume you start with identification; criteria must come first to make identification meaningful
Treating "evaluate" and "analyse" as identicalISO 27001 separates them; "analyse" = calculate risk levels, "evaluate" = compare to criteria and prioritise

Bottom line: The sequence follows a strict logical dependency chain - you define, then discover, then understand, then act. Each step is prerequisite to the next.

Topics

#risk assessment process#ISMS#risk identification#risk evaluation

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice