LEAD-AUDITOR · Question #332
Drag and Drop Question You have just completed a scheduled information security audit of your organisation when the IT Manager approaches you and asks for your assistance in the revision of the compan
The correct answer is This is a definition of information security risk treatment; This is a definition of information security risk; This is a definition of information security risk criteria; This is a definition of information security risk acceptance criteria. Important Note on the Question The actual description texts (the items being dragged) are not shown in the question - only the term labels are visible. However, based on ISO/IEC 27005 (Information Security Risk Management) and ISO 27001, I can explain what each term means and why
Question
Drag and Drop Question You have just completed a scheduled information security audit of your organisation when the IT Manager approaches you and asks for your assistance in the revision of the company's risk management process. He is attempting to update the current documentation to make it easier for other managers to understand, however, it is clear from your discussion he is confusing several key terms. You ask him to match each of the descriptions with the appropriate risk term. What should the correct answers be? Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- This is a definition of information security risk treatment
- This is a definition of information security risk
- This is a definition of information security risk criteria
- This is a definition of information security risk acceptance criteria
Explanation
Important Note on the Question
The actual description texts (the items being dragged) are not shown in the question - only the term labels are visible. However, based on ISO/IEC 27005 (Information Security Risk Management) and ISO 27001, I can explain what each term means and why the arrangement is correct.
The Four Terms Explained
Position 1 → Information Security Risk Treatment
Definition: The process of selecting and implementing measures to modify risk. Options include:
- Avoid the risk (stop the activity)
- Reduce the risk (apply controls)
- Share/Transfer the risk (insurance, outsourcing)
- Retain/Accept the risk (conscious decision to accept)
Risk treatment is an action - it's what you do about a risk after evaluating it.
Position 2 → Information Security Risk
Definition: The potential that a threat will exploit a vulnerability in an asset, causing harm to the organisation. Expressed as a combination of:
- Likelihood of an event occurring
- Consequence/Impact if it does occur
This is the foundational concept - the possibility of something going wrong.
Position 3 → Information Security Risk Criteria
Definition: The terms of reference used to evaluate the significance of a risk. These are organisation-defined benchmarks that determine whether a risk is acceptable, unacceptable, or requires treatment.
Think of it as the scoring framework - how you measure and compare risks consistently across the organisation.
Position 4 → Information Security Risk Acceptance Criteria
Definition: The specific thresholds or conditions under which the organisation is willing to accept a risk without further treatment. This is a subset of risk criteria, focused specifically on the acceptance decision.
Example: "Any risk scoring below 6 on our risk matrix will be accepted without further controls."
Why This Ordering Matters
| Position | Term | Key Distinguishing Feature |
|---|---|---|
| 1 | Risk Treatment | An action taken in response to risk |
| 2 | Risk | The core concept - potential for harm |
| 3 | Risk Criteria | The framework for evaluating significance |
| 4 | Risk Acceptance Criteria | A specific threshold within criteria |
Common Misconceptions
-
Risk Criteria vs. Risk Acceptance Criteria - the most common confusion. Risk criteria is the broader evaluation framework; acceptance criteria is the specific threshold for accepting risk. Acceptance criteria is a subset.
-
Risk vs. Risk Treatment - candidates often conflate the existence of a risk with what you do about it. They are separate lifecycle stages.
-
Risk Treatment is not just "controls" - candidates often think treatment means only implementing technical controls, forgetting that avoidance, transfer, and retention are also valid treatment options per ISO 27005.
-
Acceptance criteria is not optional - some candidates think it only applies when you choose to "accept" risk. In fact, every organisation must define acceptance thresholds as part of establishing their risk management framework, even if few risks fall below them.
Topics
Community Discussion
No community discussion yet for this question.
