nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #191

Drag and Drop Question You are an experienced ISMS audit team leader providing instruction to a class of auditors in training. The subject of today's lesson is the management of information security…

The correct answer is Create and maintain information security risk criteria; Identify the risks that need to be considered when planning for the information security management system; Assess the potential consequences that could arise if information security were compromised; Select appropriate risk treatment options; Carry out information security risk assessments at planned intervals; Consider the results of risk assessment and the status of risk treatment at scheduled intervals. ISO/IEC 27001:2022 - Risk Management Activity Sequence The correct order follows the clause structure of the standard itself, moving from planning through operation to performance evaluation. --- Why This Order? The sequence maps directly to ISO/IEC 27001:2022 clauses in…

Information Security Risk Management

Question

Drag and Drop Question You are an experienced ISMS audit team leader providing instruction to a class of auditors in training. The subject of today's lesson is the management of information security risk in accordance with the requirements of ISO/IEC 27001:2022. You provide the class with a series of activities. You then ask the class to sort these activities into the order in which they appear in the standard. What is the correct sequence they should report back to you? Answer:

Exhibit

ISO-IEC-27001-LEAD-AUDITOR question #191 exhibit

Answer Area

Drag items

Create and maintain information security risk criteriaIdentify the risks that need to be considered when planning for the information security management systemAssess the potential consequences that could arise if information security were compromisedSelect appropriate risk treatment optionsCarry out information security risk assessments at planned intervalsConsider the results of risk assessment and the status of risk treatment at scheduled intervals

Correct arrangement

  • Create and maintain information security risk criteria
  • Identify the risks that need to be considered when planning for the information security management system
  • Assess the potential consequences that could arise if information security were compromised
  • Select appropriate risk treatment options
  • Carry out information security risk assessments at planned intervals
  • Consider the results of risk assessment and the status of risk treatment at scheduled intervals

Explanation

ISO/IEC 27001:2022 - Risk Management Activity Sequence

The correct order follows the clause structure of the standard itself, moving from planning through operation to performance evaluation.


Why This Order?

The sequence maps directly to ISO/IEC 27001:2022 clauses in numerical order:

#ActivityClause
1Create and maintain risk criteria6.1.2(a)
2Identify risks for planning6.1.2(c)
3Assess potential consequences6.1.2(d)
4Select risk treatment options6.1.3
5Carry out assessments at planned intervals8.2
6Consider results at scheduled intervals9.3

The standard follows a Plan → Do → Check logic, and the activities follow that flow.


Item-by-Item Explanation

1. Create and maintain information security risk criteria (Clause 6.1.2(a))

This is the mandatory first step. Before you can identify or evaluate any risk, you must define what counts as a risk and what level is acceptable. Without established criteria, any subsequent assessment is arbitrary. The standard requires you to define both risk acceptance criteria and criteria for performing the assessments themselves. Everything downstream depends on this foundation.

2. Identify the risks that need to be considered when planning for the ISMS (Clause 6.1.2(c))

Only after criteria exist can you meaningfully identify risks. This step applies those criteria to discover what could go wrong - identifying assets, threats, vulnerabilities, and potential loss of confidentiality, integrity, or availability. This is still in the planning phase (Clause 6), before the ISMS is fully operational.

3. Assess the potential consequences that could arise if information security were compromised (Clause 6.1.2(d))

With risks identified, you now analyze them - estimating consequences, assessing likelihood, and determining risk levels. This is the analytic/evaluation sub-step within the same 6.1.2 clause. It comes after identification because you can't assess what you haven't yet identified.

4. Select appropriate risk treatment options (Clause 6.1.3)

Risk treatment is a separate clause (6.1.3), deliberately placed after the full assessment in 6.1.2. You can only select treatment options (modify, retain, avoid, share) once you know the risk levels. This step also produces the Statement of Applicability (SoA) and a risk treatment plan.

5. Carry out information security risk assessments at planned intervals (Clause 8.2)

This is the operational execution of what was planned in Clause 6. Clause 8 is the "Do" phase. The assessments designed and defined in planning are now actually performed - at scheduled intervals or when significant changes occur. A critical distinction from item 2: item 2 is designing the process; item 5 is running it.

6. Consider the results of risk assessment and the status of risk treatment at scheduled intervals (Clause 9.3)

This maps to management review (Clause 9.3), which is in the "Check/Act" phase. Senior management must periodically review risk assessment outcomes and treatment plan status as a mandatory input to the management review. This comes last because you can only review results after assessments have been carried out (item 5).


Common Mistakes and Misconceptions

Conflating items 2 and 5. Both involve identifying/performing risk assessments, but item 2 is the design-time activity during planning, while item 5 is the run-time operational execution. Confusing these suggests a misunderstanding of the Plan/Do/Check structure.

Placing risk treatment (item 4) before assessment (item 3). A frequent mistake. You cannot select a treatment option before you have assessed the consequence and likelihood of a risk - you wouldn't know what level of treatment is proportionate.

Placing item 6 (management review) earlier in the sequence. Some candidates mistake this for part of the planning phase. It belongs in Clause 9 (Performance Evaluation), which logically follows operation (Clause 8). You can only review results that have been generated.

Treating items 1–4 as equivalent to 5–6. Items 1–4 are largely planning activities (Clause 6); items 5–6 are operation and evaluation (Clauses 8 and 9). Understanding this distinction is key to answering sequencing questions about the standard.

Topics

#risk management process#ISO 27001 Clause 6#risk assessment#risk treatment

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice