nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #80

Drag and Drop Question You have just completed a scheduled information security audit of your organisation when the IT Manager approaches you and asks for your assistance in the revision of the…

The correct answer is This is a definition of information security risk treatment; This is a definition of information security risk; This is a definition of information security risk criteria; This is a definition of information security risk acceptance criteria. Information Security Risk Management Terms - Explained These definitions come directly from ISO 27001/27005 and ISO 31000 standards. Matching them correctly requires understanding the precise technical meaning each standard assigns to each term. --- 1. Risk Treatment → "The…

Information Security Risk Management

Question

Drag and Drop Question You have just completed a scheduled information security audit of your organisation when the IT Manager approaches you and asks for your assistance in the revision of the company's risk management process. He is attempting to update the current documentation to make it easier for other managers to understand, however, it is clear from your discussion he is confusing several key terms. You ask him to match each of the descriptions with the appropriate risk term. What should the correct answers be? Answer:

Exhibit

ISO-IEC-27001-LEAD-AUDITOR question #80 exhibit

Answer Area

Drag items

The strategy chosen to respond to a specific information security riskThe effect of uncertainty on information security objectivesThe requirements against which information security risks are evaluatedA definition of the overall level of information security risk that is considered to be tolerable

Correct arrangement

  • This is a definition of information security risk treatment
  • This is a definition of information security risk
  • This is a definition of information security risk criteria
  • This is a definition of information security risk acceptance criteria

Explanation

Information Security Risk Management Terms - Explained

These definitions come directly from ISO 27001/27005 and ISO 31000 standards. Matching them correctly requires understanding the precise technical meaning each standard assigns to each term.


1. Risk Treatment → "The strategy chosen to respond to a specific information security risk"

Why: Risk treatment is the action phase - what you decide to do about a risk once it's been identified and assessed. The four common strategies are: avoid, transfer, mitigate (reduce), or accept the risk.

Common mistake: Confusing treatment with risk acceptance. Treatment is the broader decision; acceptance is just one option within treatment.


2. Information Security Risk → "The effect of uncertainty on information security objectives"

Why: This is the verbatim ISO 31000 definition of risk. "Uncertainty" captures the probabilistic nature of threats, and "objectives" grounds it in business impact (confidentiality, integrity, availability).

Common mistake: Students often define risk informally as "a threat" or "a vulnerability." The ISO definition is more abstract - risk is the effect, not the source.


3. Risk Criteria → "The requirements against which information security risks are evaluated"

Why: Risk criteria are the benchmarks or thresholds an organisation sets before assessment - e.g., a risk scoring matrix or a policy that any risk scoring above 15 must be treated. They define the rules of evaluation.

Common mistake: Confusing criteria with acceptance criteria. Criteria is the broader evaluation framework; acceptance criteria is a specific subset of it.


4. Risk Acceptance Criteria → "A definition of the overall level of information security risk that is considered to be tolerable"

Why: This is a specific type of risk criteria - it defines the maximum tolerable risk threshold. Risks at or below this level may be consciously accepted without further treatment.

Common mistake: Assuming "acceptance" means the risk is desirable or ignored. It means the organisation has made a deliberate, documented decision that the residual risk is within acceptable bounds.


Key Hierarchy to Remember

Risk (what it is - uncertainty affecting objectives)
  ↓
Risk Criteria (how you measure/evaluate it)
  ↓ subset of
Risk Acceptance Criteria (how much is tolerable)
  ↓ feeds into
Risk Treatment (what you do about it)

The terms form a logical progression from definition → measurement → tolerance threshold → action.

Topics

#risk terminology#risk assessment#risk management process#ISO 27001 risk concepts

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice