nerdexam
PECB

LEAD-AUDITOR · Question #353

Drag and Drop Question You are an experienced ISMS audit team leader providing instruction to a class of auditors in training. The subject of today's lesson is the management of information security r

The correct answer is Create and maintain information security risk criteria; Assess the potential consequences that would arise if the risk were to materialize; Identify the risks that need to be considered when planning for the information security management system; Carry out information security risk assessments at planned intervals; Select appropriate risk treatment options; Consider the results of risk assessment and the status of the risk treatment plan at management review. ISO/IEC 27001:2022 Risk Management Activity Sequence - Explained Framework Overview ISO 27001:2022 structures risk management across three clauses in a logical flow: Clause 6.1.2: Risk assessment process (Planning phase) Clause 6.1.3: Risk treatment (Planning phase) Clause 8.2: O

Information Security Risk Management

Question

Drag and Drop Question You are an experienced ISMS audit team leader providing instruction to a class of auditors in training. The subject of today's lesson is the management of information security risk in accordance with the requirements of ISO/IEC 27001:2022. You provide the class with a series of activities. You then ask the class to sort these activities into the order in which they appear in the standard. What is the correct sequence they should report back to you? Answer:

Exhibit

LEAD-AUDITOR question #353 exhibit

Answer Area

Drag items

Create and maintain information security risk criteriaIdentify the risks that need to be considered when planning for the information security management systemAccess the potential consequences that would arise if the risk were to materializeSelect appropriate risk treatment optionsConsider the results of risk assessment and the status of the risk treatment plan at management reviewCarry out information security risk assessments at planned intervals

Correct arrangement

  • Create and maintain information security risk criteria
  • Assess the potential consequences that would arise if the risk were to materialize
  • Identify the risks that need to be considered when planning for the information security management system
  • Carry out information security risk assessments at planned intervals
  • Select appropriate risk treatment options
  • Consider the results of risk assessment and the status of the risk treatment plan at management review

Explanation

ISO/IEC 27001:2022 Risk Management Activity Sequence - Explained

Framework Overview

ISO 27001:2022 structures risk management across three clauses in a logical flow:

  • Clause 6.1.2: Risk assessment process (Planning phase)
  • Clause 6.1.3: Risk treatment (Planning phase)
  • Clause 8.2: Operational execution of assessments
  • Clause 9.3: Management review (Check phase)

The sequence moves from establishing the frameworkdesigning the processexecuting operationallygoverning via review.


Item-by-Item Breakdown

1. Create and maintain information security risk criteria (Clause 6.1.2(a))

This is correctly first. Before any risk work can begin, you must establish the rules of the game - what counts as a risk, what acceptance thresholds look like, and how assessments will be measured. Without defined criteria, identification and analysis have no baseline to work against. Criteria are a prerequisite, not an output.

Common mistake: Thinking you identify risks first, then figure out how to judge them. The standard explicitly requires criteria to be established before risks are identified.


2. Assess the potential consequences that would arise if the risk were to materialize (Clause 6.1.2(d)(1))

This refers to defining how consequence assessment will work as part of building the risk assessment methodology - i.e., you establish what "consequence" means (impact on confidentiality, integrity, availability) and how it will be scored before applying it to specific identified risks. This is part of designing the assessment process.

Common mistake / point of confusion: In practical risk management, you'd typically identify risks before assessing their consequences. The exam places this second because it's treated here as defining the consequence assessment methodology - a design decision made before you go looking for specific risks.


3. Identify the risks that need to be considered when planning for the information security management system (Clause 6.1.2(c) / 6.1.1)

Once the criteria are set and the assessment methodology is defined, you apply the process to identify specific risks - those associated with loss of confidentiality, integrity, and availability within the ISMS scope. The phrase "when planning for the ISMS" signals this is tied to the Planning phase, where risks are catalogued for the system as a whole.

Common mistake: Confusing this with Clause 6.1.1 (which mentions determining "risks and opportunities" at a strategic ISMS planning level). The distinction matters: 6.1.1 is about why you're doing risk management; 6.1.2(c) is the actual identification step.


4. Carry out information security risk assessments at planned intervals (Clause 8.2)

This shifts from planning the process (Clause 6) to operating it (Clause 8). Clause 8.2 requires that the organization actually execute the risk assessment process that was designed in 6.1.2 - regularly and at defined intervals. This is the "Do" phase of PDCA.

Common mistake: Thinking Clause 8.2 duplicates 6.1.2. Clause 6 designs the methodology; Clause 8 mandates its operational execution. They serve different purposes.


5. Select appropriate risk treatment options (Clause 6.1.3(a))

After risks are identified and assessed, treatment options are selected. ISO 27001 offers four standard options: modify (mitigate), retain (accept), avoid, or share (transfer) the risk. This step only makes sense after you know what risks exist and how severe they are.

Common mistake: Jumping to treatment before completing the assessment. The standard is explicit that treatment follows from assessment results - you cannot select appropriate controls without first understanding the risk landscape.


6. Consider the results of risk assessment and the status of the risk treatment plan at management review (Clause 9.3)

This is correctly last. Management review (Clause 9.3) is a Check phase activity where top management examines whether the ISMS is performing adequately. Risk assessment results and treatment plan status are mandatory inputs to this review. It's a governance checkpoint, not an operational step.

Common mistake: Treating management review as optional or informal. The standard mandates it as a structured, documented activity with defined inputs - including risk outputs - that feeds into continual improvement decisions.


Key Takeaway

The sequence follows PDCA logic mapped to clause structure:

#ActivityClausePDCA
1Establish risk criteria6.1.2(a)Plan
2Define consequence assessment6.1.2(d)Plan
3Identify specific risks6.1.2(c)Plan
4Execute assessments operationally8.2Do
5Select treatment options6.1.3Plan/Do
6Management review9.3Check

The most counterintuitive ordering is items 2 and 3 - consequences before identification. The exam's rationale treats "assess consequences" as defining the methodology (part of the framework design), while "identify risks" refers to applying that methodology to find actual risks. Keep this distinction in mind when encountering similar questions.

Topics

#risk management sequence#ISO 27001:2022#risk assessment#risk treatment

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice