Information Security Risk Management Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Information Security Risk Management flashcards as text
In ISO 27000 terminology, which term refers to the combination of the probability of an event and its consequence?
Answer: Risk
Risk is defined as the effect of uncertainty on objectives, typically expressed as the combination of likelihood and impact.
An organization scores each risk by multiplying a likelihood score (1–5) by an impact score (1–5). This approach is an example of which assessment method?
Answer: Semi-quantitative assessment
Semi-quantitative assessment uses numerical scales (like 1–5) that are ordinal rather than true monetary values, combining elements of both qualitative and quantitative approaches.
Which process ensures that the ISMS risk treatment remains effective as the organization's environment changes over time?
Answer: Risk monitoring and review
Risk monitoring and review is an ongoing process that verifies whether risk treatment measures remain effective and whether new risks have emerged.
Under ISO 27001, which document formally records top management's decision to accept residual risks?
Answer: Signed risk acceptance records
Formal records of risk acceptance decisions must be maintained and are typically documented as signed acceptance statements by authorized risk owners.
The Annual Loss Expectancy (ALE) calculation is associated with which type of risk assessment methodology?
Answer: Quantitative
ALE (Single Loss Expectancy × Annual Rate of Occurrence) is a quantitative method that expresses risk in monetary terms.
Which of the following is an example of a PREVENTIVE control in information security risk management?
Answer: Access control policies
Preventive controls, like access control policies, are designed to stop security incidents from occurring in the first place.
According to ISO 27005, risk context establishment should include defining which of the following?
Answer: The organization's basic criteria, scope, and boundaries for risk management
Establishing context defines the scope, boundaries, and criteria that will guide the entire risk management process.