LEAD-AUDITOR · Question #265
A marketing agency has developed its risk assessment approach as part of the ISMS implementation. Is this acceptable?
The correct answer is A. Yes, any risk assessment methodology that complies with the ISO/IEC 27001 requirements can be. ISO/IEC 27001 Clause 6.1.2 (Information Security Risk Assessment) states that organizations may define their own risk assessment methodology. This approach must be systematic, measurable, and aligned with business objectives.
Question
A marketing agency has developed its risk assessment approach as part of the ISMS implementation. Is this acceptable?
Options
- AYes, any risk assessment methodology that complies with the ISO/IEC 27001 requirements can be
- BYes, only if the risk assessment methodology is aligned with recognized risk assessment
- CNo, the risk assessment methodology provided by ISO/IEC 27001 should be used when
How the community answered
(42 responses)- A88% (37)
- B7% (3)
- C5% (2)
Explanation
ISO/IEC 27001 Clause 6.1.2 (Information Security Risk Assessment) states that organizations may define their own risk assessment methodology. This approach must be systematic, measurable, and aligned with business objectives.
Topics
Community Discussion
No community discussion yet for this question.