nerdexam
PECB

LEAD-AUDITOR · Question #176

A marketing agency has developed its own risk assessment approach as part of the ISMS implementation. Is this acceptable?

The correct answer is A. Yes, any risk assessment methodology that complies with the ISO/IEC 27001 requirements can be. ISO/IEC 27001 does not mandate the use of a specific risk assessment methodology. Organizations are free to choose their own approach as long as it is systematic, consistent, and capable of producing valid and comparable results. This allows organizations, such as the marketing a

ISO/IEC 27001 Risk Assessment

Question

A marketing agency has developed its own risk assessment approach as part of the ISMS implementation. Is this acceptable?

Options

  • AYes, any risk assessment methodology that complies with the ISO/IEC 27001 requirements can be
  • BYes, only if the risk assessment methodology is aligned with recognized risk assessment
  • CNo, when implementing an ISMS, the risk assessment methodology provided by ISO/IEC 27001

How the community answered

(26 responses)
  • A
    77% (20)
  • B
    8% (2)
  • C
    15% (4)

Explanation

ISO/IEC 27001 does not mandate the use of a specific risk assessment methodology. Organizations are free to choose their own approach as long as it is systematic, consistent, and capable of producing valid and comparable results. This allows organizations, such as the marketing agency in the question, to adapt the methodology to suit their specific needs and business context, provided it complies with the requirements set out in the standard.

Topics

#risk assessment methodology#ISO 27001 requirements#ISMS implementation#risk management

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice