ISO 27000 Foundation Certification Information Security Risk Management 5 — Questions and Answers
Question 1: Which of the following BEST describes 'information security risk treatment' according to ISO 27005?
- Identifying and listing all risks in the organization's environment
- Selecting and implementing measures to modify risk (Correct answer)
- Evaluating risks against pre-defined acceptance criteria
- Communicating risk results to senior management
Correct answer: Selecting and implementing measures to modify risk
Risk treatment is the process of selecting and implementing options to address risk, which may include modifying, avoiding, sharing, or retaining it.
Question 2: A risk owner is BEST described as which of the following?
- The person who caused the security incident
- The individual accountable for managing a specific risk (Correct answer)
- The auditor responsible for reviewing risk documentation
- The vendor supplying risk management software
Correct answer: The individual accountable for managing a specific risk
A risk owner is the person or entity with the accountability and authority to manage a particular risk.
Question 3: Which ISO/IEC standard provides guidelines specifically on information security risk management and supports ISO 27001 implementation?
- ISO/IEC 27002
- ISO/IEC 27003
- ISO/IEC 27005 (Correct answer)
- ISO/IEC 27035
Correct answer: ISO/IEC 27005
ISO/IEC 27005 provides guidelines on information security risk management and is aligned with the concepts of ISO/IEC 27001.
Question 4: When an organization identifies a risk but determines that the cost of treatment exceeds the potential loss, it may decide to:
- Share the risk with a third-party insurer
- Avoid the risk by eliminating the related activity
- Retain the risk and monitor it (Correct answer)
- Transfer the risk to a business partner
Correct answer: Retain the risk and monitor it
Risk retention is appropriate when treatment costs exceed the potential impact, and the organization consciously accepts the risk.
Question 5: Which of the following is a key characteristic of a good information security risk assessment process?
- It is performed once during ISMS implementation and never repeated
- It produces results that are repeatable and comparable over time (Correct answer)
- It focuses exclusively on technical vulnerabilities in IT systems
- It is conducted solely by external consultants to avoid bias
Correct answer: It produces results that are repeatable and comparable over time
A good risk assessment process should be repeatable and produce consistent, comparable results that can be tracked over time.
Question 6: In ISO 27000, the term 'control' is BEST defined as:
- A legal mandate imposed by government regulation
- A measure that modifies risk, including policies, procedures, and technical safeguards (Correct answer)
- An audit finding requiring immediate corrective action
- The documented result of a risk assessment
Correct answer: A measure that modifies risk, including policies, procedures, and technical safeguards
ISO 27000 defines a control as a measure that modifies risk, encompassing policies, procedures, guidelines, and technical or physical safeguards.
Question 7: Which of the following scenarios demonstrates the risk management principle of 'proportionality'?
- Applying the same set of controls to every asset regardless of its value
- Spending $500,000 on controls to protect an asset worth $10,000
- Selecting controls whose cost and effort are commensurate with the risk level (Correct answer)
- Rejecting all risks above a medium rating without cost analysis
Correct answer: Selecting controls whose cost and effort are commensurate with the risk level
Proportionality means that the effort and cost of controls should be appropriate to the significance and value of the asset and the level of risk.
Which of the following BEST describes 'information security risk treatment' according to ISO 27005?