Information Security Risk Management Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Security Risk Management flashcards as text
Which of the following BEST describes 'information security risk treatment' according to ISO 27005?
Answer: Selecting and implementing measures to modify risk
Risk treatment is the process of selecting and implementing options to address risk, which may include modifying, avoiding, sharing, or retaining it.
A risk owner is BEST described as which of the following?
Answer: The individual accountable for managing a specific risk
A risk owner is the person or entity with the accountability and authority to manage a particular risk.
Which ISO/IEC standard provides guidelines specifically on information security risk management and supports ISO 27001 implementation?
Answer: ISO/IEC 27005
ISO/IEC 27005 provides guidelines on information security risk management and is aligned with the concepts of ISO/IEC 27001.
When an organization identifies a risk but determines that the cost of treatment exceeds the potential loss, it may decide to:
Answer: Retain the risk and monitor it
Risk retention is appropriate when treatment costs exceed the potential impact, and the organization consciously accepts the risk.
Which of the following is a key characteristic of a good information security risk assessment process?
Answer: It produces results that are repeatable and comparable over time
A good risk assessment process should be repeatable and produce consistent, comparable results that can be tracked over time.
In ISO 27000, the term 'control' is BEST defined as:
Answer: A measure that modifies risk, including policies, procedures, and technical safeguards
ISO 27000 defines a control as a measure that modifies risk, encompassing policies, procedures, guidelines, and technical or physical safeguards.
Which of the following scenarios demonstrates the risk management principle of 'proportionality'?
Answer: Selecting controls whose cost and effort are commensurate with the risk level
Proportionality means that the effort and cost of controls should be appropriate to the significance and value of the asset and the level of risk.