PECB
LEAD-IMPLEMENTER · Question #292
What criteria should organizations use to determine acceptable levels of risk in ISO 27001?
The correct answer is A. Risk appetite and tolerance levels. See the full explanation below for the reasoning.
Question
What criteria should organizations use to determine acceptable levels of risk in ISO 27001?
Options
- ARisk appetite and tolerance levels
- BPast incident analysis
- CStakeholder opinions
- DRegulatory compliance requirements
How the community answered
(17 responses)- A76% (13)
- B6% (1)
- C6% (1)
- D12% (2)
Community Discussion
No community discussion yet for this question.