ITSM20F · Question #81
Which of the following is a best practice concerning information security risk assessment?
The correct answer is C. Information security risk assessments should be performed at agreed intervals and be. Option C reflects the guidance in ISO/IEC 27001, which requires that risk assessments be performed at planned, agreed-upon intervals and whenever significant changes occur - ensuring they remain current without being unnecessarily triggered by every minor event. Why the…
Question
Which of the following is a best practice concerning information security risk assessment?
Options
- AInformation security risk assessments should be carried out by an external auditor to maintain
- BInformation security risk assessments should be performed as a result of the review of every
- CInformation security risk assessments should be performed at agreed intervals and be
- DInformation security risk assessments should be performed once a year.
How the community answered
(48 responses)- A2% (1)
- B6% (3)
- C88% (42)
- D4% (2)
Explanation
Option C reflects the guidance in ISO/IEC 27001, which requires that risk assessments be performed at planned, agreed-upon intervals and whenever significant changes occur - ensuring they remain current without being unnecessarily triggered by every minor event.
Why the distractors are wrong:
- A is incorrect because risk assessments do not need to be performed by an external auditor; internal teams with appropriate competence can conduct them, and independence doesn't require external parties.
- B is incorrect because tying assessments to every review or change would be impractical and resource-intensive; assessments are triggered by significant changes or scheduled intervals, not every single event.
- D is incorrect because prescribing once a year is too rigid - some environments require more frequent assessments based on threat landscape changes or organizational risk appetite.
Memory tip: Think of risk assessments like health check-ups - you schedule them at regular agreed intervals (not just once a year arbitrarily, and not after every meal), and you go sooner if something significant changes. "Agreed intervals" = flexible, risk-driven scheduling, which is the hallmark of mature security governance.
Topics
Community Discussion
No community discussion yet for this question.