nerdexam
EXIN

ITSM20F · Question #81

Which of the following is a best practice concerning information security risk assessment?

The correct answer is C. Information security risk assessments should be performed at agreed intervals and be. Option C reflects the guidance in ISO/IEC 27001, which requires that risk assessments be performed at planned, agreed-upon intervals and whenever significant changes occur - ensuring they remain current without being unnecessarily triggered by every minor event. Why the…

Control processes

Question

Which of the following is a best practice concerning information security risk assessment?

Options

  • AInformation security risk assessments should be carried out by an external auditor to maintain
  • BInformation security risk assessments should be performed as a result of the review of every
  • CInformation security risk assessments should be performed at agreed intervals and be
  • DInformation security risk assessments should be performed once a year.

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    6% (3)
  • C
    88% (42)
  • D
    4% (2)

Explanation

Option C reflects the guidance in ISO/IEC 27001, which requires that risk assessments be performed at planned, agreed-upon intervals and whenever significant changes occur - ensuring they remain current without being unnecessarily triggered by every minor event.

Why the distractors are wrong:

  • A is incorrect because risk assessments do not need to be performed by an external auditor; internal teams with appropriate competence can conduct them, and independence doesn't require external parties.
  • B is incorrect because tying assessments to every review or change would be impractical and resource-intensive; assessments are triggered by significant changes or scheduled intervals, not every single event.
  • D is incorrect because prescribing once a year is too rigid - some environments require more frequent assessments based on threat landscape changes or organizational risk appetite.

Memory tip: Think of risk assessments like health check-ups - you schedule them at regular agreed intervals (not just once a year arbitrarily, and not after every meal), and you go sooner if something significant changes. "Agreed intervals" = flexible, risk-driven scheduling, which is the hallmark of mature security governance.

Topics

#information security#risk assessment#security management#best practices

Community Discussion

No community discussion yet for this question.

Full ITSM20F Practice