nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #308

A marketing agency has developed its risk assessment approach as part of the ISMS implementation. Is this acceptable?

The correct answer is A. Yes, any risk assessment methodology that complies with the ISO/IEC 27001 requirements can. ISO/IEC 27001 does not prescribe a specific risk assessment methodology but instead provides general requirements for risk assessment. Organizations are free to develop their own risk assessment methods, as long as they: Identify risks and impacts on information security…

Risk Assessment and Treatment

Question

A marketing agency has developed its risk assessment approach as part of the ISMS implementation. Is this acceptable?

Options

  • AYes, any risk assessment methodology that complies with the ISO/IEC 27001 requirements can
  • BYes, only if the risk assessment methodology is aligned with recognized risk assessment
  • CNo, the risk assessment methodology provided by ISO/IEC 27001 should be used when

How the community answered

(39 responses)
  • A
    87% (34)
  • B
    3% (1)
  • C
    10% (4)

Explanation

ISO/IEC 27001 does not prescribe a specific risk assessment methodology but instead provides general requirements for risk assessment. Organizations are free to develop their own risk assessment methods, as long as they: Identify risks and impacts on information security. Define risk criteria for evaluating risks. Implement risk treatment plans based on the organization's context. ISO/IEC 27001 Clause 6.1.2 (Information Security Risk Assessment) states that organizations may define their own risk assessment methodology. This approach must be systematic, measurable, and aligned with business objectives.

Topics

#risk assessment methodology#ISO/IEC 27001 flexibility#risk management#Clause 6.1

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice