ISO-IEC-27001-LEAD-AUDITOR · Question #191
Drag and Drop Question You are an experienced ISMS audit team leader providing instruction to a class of auditors in training. The subject of today's lesson is the management of information security…
The correct answer is Create and maintain information security risk criteria; Identify the risks that need to be considered when planning for the information security management system; Assess the potential consequences that could arise if information security were compromised; Select appropriate risk treatment options; Carry out information security risk assessments at planned intervals; Consider the results of risk assessment and the status of risk treatment at scheduled intervals. ISO/IEC 27001:2022 - Risk Management Activity Sequence The correct order follows the clause structure of the standard itself, moving from planning through operation to performance evaluation. --- Why This Order? The sequence maps directly to ISO/IEC 27001:2022 clauses in…
Question
Drag and Drop Question You are an experienced ISMS audit team leader providing instruction to a class of auditors in training. The subject of today's lesson is the management of information security risk in accordance with the requirements of ISO/IEC 27001:2022. You provide the class with a series of activities. You then ask the class to sort these activities into the order in which they appear in the standard. What is the correct sequence they should report back to you? Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- Create and maintain information security risk criteria
- Identify the risks that need to be considered when planning for the information security management system
- Assess the potential consequences that could arise if information security were compromised
- Select appropriate risk treatment options
- Carry out information security risk assessments at planned intervals
- Consider the results of risk assessment and the status of risk treatment at scheduled intervals
Explanation
ISO/IEC 27001:2022 - Risk Management Activity Sequence
The correct order follows the clause structure of the standard itself, moving from planning through operation to performance evaluation.
Why This Order?
The sequence maps directly to ISO/IEC 27001:2022 clauses in numerical order:
| # | Activity | Clause |
|---|---|---|
| 1 | Create and maintain risk criteria | 6.1.2(a) |
| 2 | Identify risks for planning | 6.1.2(c) |
| 3 | Assess potential consequences | 6.1.2(d) |
| 4 | Select risk treatment options | 6.1.3 |
| 5 | Carry out assessments at planned intervals | 8.2 |
| 6 | Consider results at scheduled intervals | 9.3 |
The standard follows a Plan → Do → Check logic, and the activities follow that flow.
Item-by-Item Explanation
1. Create and maintain information security risk criteria (Clause 6.1.2(a))
This is the mandatory first step. Before you can identify or evaluate any risk, you must define what counts as a risk and what level is acceptable. Without established criteria, any subsequent assessment is arbitrary. The standard requires you to define both risk acceptance criteria and criteria for performing the assessments themselves. Everything downstream depends on this foundation.
2. Identify the risks that need to be considered when planning for the ISMS (Clause 6.1.2(c))
Only after criteria exist can you meaningfully identify risks. This step applies those criteria to discover what could go wrong - identifying assets, threats, vulnerabilities, and potential loss of confidentiality, integrity, or availability. This is still in the planning phase (Clause 6), before the ISMS is fully operational.
3. Assess the potential consequences that could arise if information security were compromised (Clause 6.1.2(d))
With risks identified, you now analyze them - estimating consequences, assessing likelihood, and determining risk levels. This is the analytic/evaluation sub-step within the same 6.1.2 clause. It comes after identification because you can't assess what you haven't yet identified.
4. Select appropriate risk treatment options (Clause 6.1.3)
Risk treatment is a separate clause (6.1.3), deliberately placed after the full assessment in 6.1.2. You can only select treatment options (modify, retain, avoid, share) once you know the risk levels. This step also produces the Statement of Applicability (SoA) and a risk treatment plan.
5. Carry out information security risk assessments at planned intervals (Clause 8.2)
This is the operational execution of what was planned in Clause 6. Clause 8 is the "Do" phase. The assessments designed and defined in planning are now actually performed - at scheduled intervals or when significant changes occur. A critical distinction from item 2: item 2 is designing the process; item 5 is running it.
6. Consider the results of risk assessment and the status of risk treatment at scheduled intervals (Clause 9.3)
This maps to management review (Clause 9.3), which is in the "Check/Act" phase. Senior management must periodically review risk assessment outcomes and treatment plan status as a mandatory input to the management review. This comes last because you can only review results after assessments have been carried out (item 5).
Common Mistakes and Misconceptions
Conflating items 2 and 5. Both involve identifying/performing risk assessments, but item 2 is the design-time activity during planning, while item 5 is the run-time operational execution. Confusing these suggests a misunderstanding of the Plan/Do/Check structure.
Placing risk treatment (item 4) before assessment (item 3). A frequent mistake. You cannot select a treatment option before you have assessed the consequence and likelihood of a risk - you wouldn't know what level of treatment is proportionate.
Placing item 6 (management review) earlier in the sequence. Some candidates mistake this for part of the planning phase. It belongs in Clause 9 (Performance Evaluation), which logically follows operation (Clause 8). You can only review results that have been generated.
Treating items 1–4 as equivalent to 5–6. Items 1–4 are largely planning activities (Clause 6); items 5–6 are operation and evaluation (Clauses 8 and 9). Understanding this distinction is key to answering sequencing questions about the standard.
Topics
Community Discussion
No community discussion yet for this question.
