Risk Assessment and Treatment Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Assessment and Treatment flashcards as text
What is the role of the Statement of Applicability (SoA) in relation to risk treatment?
Answer: It documents which Annex A controls are applicable and justifies inclusions or exclusions
The SoA maps the selected controls to identified risks and justifies why each Annex A control is included or excluded.
An organization implements multi-factor authentication to reduce the risk of unauthorized access. This is an example of which type of control?
Answer: Preventive control
Multi-factor authentication prevents unauthorized access from occurring, making it a preventive control.
Which of the following BEST describes risk evaluation in the ISO 27005 process?
Answer: Comparing estimated risk levels against risk criteria to prioritize treatment
Risk evaluation involves comparing risk estimates against acceptance criteria to determine which risks require treatment and in what order.
A company keeps a small amount of sensitive data on an unencrypted laptop and decides the cost of a breach is acceptable given the low probability. This decision represents:
Answer: Risk retention
Knowingly accepting a risk without applying additional controls, because the expected impact is acceptable, is risk retention.
Which of the following is TRUE about the relationship between assets, threats, and vulnerabilities in risk assessment?
Answer: Risk arises when a threat exploits a vulnerability affecting an asset
Risk materializes when a threat agent exploits a vulnerability to cause harm to an asset, combining all three elements.
How often does ISO/IEC 27001 require organizations to perform information security risk assessments?
Answer: At planned intervals and when significant changes occur
ISO/IEC 27001 requires risk assessments at planned intervals and whenever significant changes arise that may affect information security.
Which quantitative measure expresses the expected monetary loss from a specific threat occurring once?
Answer: Single Loss Expectancy (SLE)
Single Loss Expectancy (SLE) represents the monetary loss expected each time a specific threat event occurs.