nerdexam
PECB

LEAD-AUDITOR · Question #101

You are an experienced ISMS audit team leader conducting a third-party surveillance audit of an internet services provider. You are reviewing the organization's risk assessment processes for conformit

The correct answer is B. The organisation is treating information security risks in the order in which they are identified E. The organisation's risk assessment criteria have not been reviewed and approved by top F. The organisation's information security risk assessment process is based solely on an assessment. You've hit your limit · resets 4am (America/New_York)

Risk Assessment and Treatment

Question

You are an experienced ISMS audit team leader conducting a third-party surveillance audit of an internet services provider. You are reviewing the organization's risk assessment processes for conformity with ISO/IEC 27001:2022. Which three of the following audit findings would prompt you to raise a nonconformity report?

Options

  • ABoth systems contain additional information security risks which are not associated with preserving
  • BThe organisation is treating information security risks in the order in which they are identified
  • CThe organisation's information security risk assessment process suggests each risk is allocated a
  • DThe organisation has not used RAG (Red, Amber, Green) to classify its' information security risks.
  • EThe organisation's risk assessment criteria have not been reviewed and approved by top
  • FThe organisation's information security risk assessment process is based solely on an assessment
  • GThe organisation has assessed the probability of all of its information security risks as either 0%,
  • HThere is a different system in place for assessing operational information security risks and for

How the community answered

(56 responses)
  • A
    2% (1)
  • B
    68% (38)
  • C
    9% (5)
  • D
    16% (9)
  • G
    2% (1)
  • H
    4% (2)

Explanation

You've hit your limit · resets 4am (America/New_York)

Topics

#risk assessment#nonconformity identification#ISO 27001:2022#risk criteria

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice