nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #84

You are an experienced ISMS audit team leader. During the conducting of a third-party surveillance audit, you decide to test your auditee's knowledge of ISO/IEC 27001's risk management requirements…

The correct answer is A. The results of risk assessments must be maintained C. ISO/IEC 27001 provides an outline approach for the management of risk D. The organisation must produce a risk treatment plan for every business risk identified H. Risk assessments should be undertaken following significant changes. The following four statements are true according to ISO/IEC 27001's risk management requirements: 12 The results of risk assessments must be maintained. This is true because clause 8.2.3 of ISO/IEC 27001:2022 requires the organisation to retain documented information of the…

Information Security Risk Management

Question

You are an experienced ISMS audit team leader. During the conducting of a third-party surveillance audit, you decide to test your auditee's knowledge of ISO/IEC 27001's risk management requirements. You ask her a series of questions to which the answer is either 'that is true' or 'that is false'. Which four of the following should she answer 'that is true'?

Options

  • AThe results of risk assessments must be maintained
  • BRisk identification is used to determine the severity of an information security risk
  • CISO/IEC 27001 provides an outline approach for the management of risk
  • DThe organisation must produce a risk treatment plan for every business risk identified
  • EThe organisation must operate a risk treatment process to eliminate it's information security risks
  • FThe initial phase in an organisation's risk management process should be information security risk
  • GRisks assessments should be undertaken at monthly intervals
  • HRisk assessments should be undertaken following significant changes

How the community answered

(21 responses)
  • A
    90% (19)
  • B
    5% (1)
  • F
    5% (1)

Explanation

The following four statements are true according to ISO/IEC 27001's risk management requirements: 12 The results of risk assessments must be maintained. This is true because clause 8.2.3 of ISO/IEC 27001:2022 requires the organisation to retain documented information of the information security risk assessment process and the results12 ISO/IEC 27001 provides an outline approach for the management of risk. This is true because clause 6.1.2 of ISO/IEC 27001:2022 specifies the general steps for the information security risk management process, which include establishing the risk criteria, assessing the risks, treating the risks, and monitoring and reviewing the risks12 The organisation must produce a risk treatment plan for every business risk identified. This is true because clause 6.1.3 of ISO/IEC 27001:2022 requires the organisation to produce a risk treatment plan that defines the actions to be taken to address the unacceptable risks, the responsibilities, the expected dates, and the resources required12 Risk assessments should be undertaken following significant changes. This is true because clause 8.2.4 of ISO/IEC 27001:2022 requires the organisation to review and update the risk assessment at planned intervals or when significant changes occur12

Topics

#risk assessment#risk treatment plan#risk management process#ISO 27001 clause 6

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice