nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #219

A marketing agency has developed its own risk assessment approach as part of the ISMS implementation. Is this acceptable?

The correct answer is A. Yes, any risk assessment methodology that complies with the ISO/IEC 27001 requirements can. ISO/IEC 27001 does not mandate the use of a specific risk assessment methodology. Organizations are free to choose their own approach as long as it is systematic, consistent, and capable of producing valid and comparable results. This allows organizations, such as the marketing…

Risk Management

Question

A marketing agency has developed its own risk assessment approach as part of the ISMS implementation. Is this acceptable?

Options

  • AYes, any risk assessment methodology that complies with the ISO/IEC 27001 requirements can
  • BYes, only if the risk assessment methodology is aligned with recognized risk assessment
  • CNo, when implementing an ISMS, the risk assessment methodology provided by ISO/IEC 27001

How the community answered

(20 responses)
  • A
    95% (19)
  • C
    5% (1)

Explanation

ISO/IEC 27001 does not mandate the use of a specific risk assessment methodology. Organizations are free to choose their own approach as long as it is systematic, consistent, and capable of producing valid and comparable results. This allows organizations, such as the marketing agency in the question, to adapt the methodology to suit their specific needs and business context, provided it complies with the requirements set out in the standard.

Topics

#risk assessment methodology#ISO 27001 compliance#custom methodology#risk process

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice