nerdexam
PECB

LEAD-AUDITOR · Question #265

A marketing agency has developed its risk assessment approach as part of the ISMS implementation. Is this acceptable?

The correct answer is A. Yes, any risk assessment methodology that complies with the ISO/IEC 27001 requirements can be. ISO/IEC 27001 Clause 6.1.2 (Information Security Risk Assessment) states that organizations may define their own risk assessment methodology. This approach must be systematic, measurable, and aligned with business objectives.

Risk Assessment and Treatment

Question

A marketing agency has developed its risk assessment approach as part of the ISMS implementation. Is this acceptable?

Options

  • AYes, any risk assessment methodology that complies with the ISO/IEC 27001 requirements can be
  • BYes, only if the risk assessment methodology is aligned with recognized risk assessment
  • CNo, the risk assessment methodology provided by ISO/IEC 27001 should be used when

How the community answered

(42 responses)
  • A
    88% (37)
  • B
    7% (3)
  • C
    5% (2)

Explanation

ISO/IEC 27001 Clause 6.1.2 (Information Security Risk Assessment) states that organizations may define their own risk assessment methodology. This approach must be systematic, measurable, and aligned with business objectives.

Topics

#risk assessment methodology#ISO/IEC 27001 compliance#ISMS flexibility#risk management

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice