Information Security Risk Management Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Security Risk Management flashcards as text
Which ISO/IEC 27005 process step involves determining the consequences of a risk materializing?
Answer: Risk estimation
Risk estimation involves determining the likelihood and consequences (impact) of a risk to produce a level of risk.
An organization decides to purchase cyber-insurance to address a specific information security risk. Which risk treatment option does this represent?
Answer: Risk sharing
Risk sharing (also called risk transfer) involves distributing the financial burden of a risk to a third party such as an insurer.
In the context of ISO 27001, what is the PRIMARY purpose of a Statement of Applicability (SoA)?
Answer: To document which Annex A controls are applicable and their justification
The SoA documents which of the ISO 27001 Annex A controls have been selected or excluded and the reasons why.
What distinguishes a 'vulnerability' from a 'threat' in information security risk terminology?
Answer: A threat is a potential cause of harm; a vulnerability is a weakness that can be exploited by a threat
ISO 27000 defines a threat as a potential cause of an unwanted incident, while a vulnerability is a weakness that may be exploited by one or more threats.
Which term describes the risk that remains after risk treatment controls have been applied?
Answer: Residual risk
Residual risk is the level of risk remaining after controls and other risk treatment measures have been implemented.
Who is ultimately accountable for approving the organization's information security risk treatment plan according to ISO 27001?
Answer: Top management
ISO 27001 requires top management to approve the risk treatment plan and accept residual risks.
A company stops offering an online service because the associated data-breach risk is too high. Which risk treatment option has been applied?
Answer: Risk avoidance
Risk avoidance involves deciding not to start or continue an activity that gives rise to the risk.