Risk Assessment and Treatment Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Assessment and Treatment flashcards as text
Which term describes the combination of the likelihood of a threat exploiting a vulnerability and the resulting impact on the organization?
Answer: Risk
Risk is defined as the combination of the probability of a threat event occurring and the magnitude of its impact.
In ISO 27005, which step directly follows risk identification in the risk assessment process?
Answer: Risk estimation
Risk estimation follows risk identification and involves assigning values to the likelihood and impact of identified risks.
An organization decides to purchase cyber insurance to handle a particular information security risk. Which risk treatment option does this represent?
Answer: Risk sharing
Transferring risk via insurance is an example of risk sharing, where the financial consequence is distributed to another party.
What is the PRIMARY purpose of establishing a risk acceptance criteria in an ISMS?
Answer: To define the level of risk the organization is willing to tolerate
Risk acceptance criteria set the threshold above which risks require treatment and below which residual risks may be accepted.
Which of the following BEST describes a qualitative risk assessment approach?
Answer: Uses descriptive scales such as high, medium, and low to rate likelihood and impact
Qualitative risk assessment uses subjective descriptive scales rather than precise numerical calculations.
When a risk owner accepts a residual risk after controls are applied, what document typically formalizes this decision?
Answer: Risk acceptance record
A risk acceptance record formally documents that the risk owner has reviewed and accepted the residual risk.
Which factor is considered when estimating the likelihood of a threat in an ISO 27005 risk assessment?
Answer: The motivation and capability of potential threat agents
Likelihood estimation considers threat agent attributes such as motivation, capability, and the opportunity presented by existing vulnerabilities.