Risk Assessment and Treatment Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Assessment and Treatment flashcards as text
When selecting risk treatment options, which ISO/IEC 27001 principle requires that control costs should be proportionate to the risks they address?
Answer: Cost-benefit analysis
ISO/IEC 27001 encourages cost-benefit analysis to ensure that the cost of implementing a control does not exceed the value of the risk being mitigated.
An organization uses a heat map with color-coded cells to communicate risk severity to senior management. What type of tool is this?
Answer: Risk matrix
A risk matrix (or heat map) plots likelihood against impact using a color-coded grid to visually communicate risk severity levels.
Which of the following scenarios BEST illustrates the risk treatment option of risk modification?
Answer: Installing a firewall to reduce the likelihood of unauthorized network access
Installing a firewall modifies (reduces) the risk by lowering the likelihood of a threat exploiting a vulnerability.
What is the PRIMARY input to the risk treatment process in an ISMS?
Answer: The results of the risk assessment
The risk assessment output, including prioritized risks and their levels, is the primary input used to determine appropriate treatment options.
In ISO/IEC 27001, which party must formally approve the risk treatment plan and accept residual risks?
Answer: Risk owners
Risk owners are responsible for approving the treatment plan for risks within their scope and formally accepting any residual risk.
A threat agent has high motivation but lacks the technical skills to exploit a complex vulnerability. How does this affect the likelihood score?
Answer: Likelihood decreases because capability is insufficient to exploit the vulnerability
Likelihood depends on both motivation and capability; without sufficient technical capability, the threat agent is unlikely to successfully exploit the vulnerability.
Which of the following is NOT typically a component recorded in a risk register?
Answer: Employee performance appraisal scores
Employee performance appraisals are an HR function and are not relevant entries in an information security risk register.