LEAD-AUDITOR · Question #63
You are an experienced ISMS audit team leader. During the conducting of a third-party surveillance audit, you decide to test your auditee's knowledge of ISO/IEC 27001's risk management requirements…
The correct answer is A. The results of risk assessments must be maintained C. ISO/IEC 27001 provides an outline approach for the management of risk D. The organisation must produce a risk treatment plan for every business risk identified H. Risk assessments should be undertaken following significant changes. You've hit your limit · resets 4am (America/New_York)
Question
You are an experienced ISMS audit team leader. During the conducting of a third-party surveillance audit, you decide to test your auditee's knowledge of ISO/IEC 27001's risk management requirements. You ask her a series of questions to which the answer is either 'that is true' or 'that is false'. Which four of the following should she answer 'that is true'?
Options
- AThe results of risk assessments must be maintained
- BRisk identification is used to determine the severity of an information security risk
- CISO/IEC 27001 provides an outline approach for the management of risk
- DThe organisation must produce a risk treatment plan for every business risk identified
- EThe organisation must operate a risk treatment process to eliminate it's information security risks
- FThe initial phase in an organisation's risk management process should be information security risk
- GRisks assessments should be undertaken at monthly intervals
- HRisk assessments should be undertaken following significant changes
How the community answered
(25 responses)- A92% (23)
- B4% (1)
- F4% (1)
Explanation
You've hit your limit · resets 4am (America/New_York)
Topics
Community Discussion
No community discussion yet for this question.