LEAD-AUDITOR · Question #101
You are an experienced ISMS audit team leader conducting a third-party surveillance audit of an internet services provider. You are reviewing the organization's risk assessment processes for conformit
The correct answer is B. The organisation is treating information security risks in the order in which they are identified E. The organisation's risk assessment criteria have not been reviewed and approved by top F. The organisation's information security risk assessment process is based solely on an assessment. You've hit your limit · resets 4am (America/New_York)
Question
You are an experienced ISMS audit team leader conducting a third-party surveillance audit of an internet services provider. You are reviewing the organization's risk assessment processes for conformity with ISO/IEC 27001:2022. Which three of the following audit findings would prompt you to raise a nonconformity report?
Options
- ABoth systems contain additional information security risks which are not associated with preserving
- BThe organisation is treating information security risks in the order in which they are identified
- CThe organisation's information security risk assessment process suggests each risk is allocated a
- DThe organisation has not used RAG (Red, Amber, Green) to classify its' information security risks.
- EThe organisation's risk assessment criteria have not been reviewed and approved by top
- FThe organisation's information security risk assessment process is based solely on an assessment
- GThe organisation has assessed the probability of all of its information security risks as either 0%,
- HThere is a different system in place for assessing operational information security risks and for
How the community answered
(56 responses)- A2% (1)
- B68% (38)
- C9% (5)
- D16% (9)
- G2% (1)
- H4% (2)
Explanation
You've hit your limit · resets 4am (America/New_York)
Topics
Community Discussion
No community discussion yet for this question.