nerdexam
PECB

LEAD-AUDITOR · Question #63

You are an experienced ISMS audit team leader. During the conducting of a third-party surveillance audit, you decide to test your auditee's knowledge of ISO/IEC 27001's risk management requirements…

The correct answer is A. The results of risk assessments must be maintained C. ISO/IEC 27001 provides an outline approach for the management of risk D. The organisation must produce a risk treatment plan for every business risk identified H. Risk assessments should be undertaken following significant changes. You've hit your limit · resets 4am (America/New_York)

Planning - Information Security Risk Management

Question

You are an experienced ISMS audit team leader. During the conducting of a third-party surveillance audit, you decide to test your auditee's knowledge of ISO/IEC 27001's risk management requirements. You ask her a series of questions to which the answer is either 'that is true' or 'that is false'. Which four of the following should she answer 'that is true'?

Options

  • AThe results of risk assessments must be maintained
  • BRisk identification is used to determine the severity of an information security risk
  • CISO/IEC 27001 provides an outline approach for the management of risk
  • DThe organisation must produce a risk treatment plan for every business risk identified
  • EThe organisation must operate a risk treatment process to eliminate it's information security risks
  • FThe initial phase in an organisation's risk management process should be information security risk
  • GRisks assessments should be undertaken at monthly intervals
  • HRisk assessments should be undertaken following significant changes

How the community answered

(25 responses)
  • A
    92% (23)
  • B
    4% (1)
  • F
    4% (1)

Explanation

You've hit your limit · resets 4am (America/New_York)

Topics

#risk assessment#risk treatment plan#risk management#ISO 27001 clause 6

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice