ISO 27000 Foundation Certification Risk Assessment and Treatment 3 — Questions and Answers
Question 1: Which ISO/IEC standard provides detailed guidance specifically on information security risk management to support ISO/IEC 27001?
- ISO/IEC 27002
- ISO/IEC 27005 (Correct answer)
- ISO/IEC 27017
- ISO/IEC 27701
Correct answer: ISO/IEC 27005
ISO/IEC 27005 is the dedicated standard providing guidelines for information security risk management aligned with ISO/IEC 27001.
Question 2: An organization stops offering an online service because the associated information security risks are too high to manage cost-effectively. Which treatment option is being used?
- Risk modification
- Risk sharing
- Risk avoidance (Correct answer)
- Risk retention
Correct answer: Risk avoidance
Discontinuing an activity to eliminate the associated risk is the definition of risk avoidance.
Question 3: What does 'residual risk' mean in the context of ISO 27001?
- Risk that has been fully eliminated by controls
- Risk remaining after risk treatment measures have been applied (Correct answer)
- Risk that has been transferred to an insurance provider
- Risk identified but not yet assessed
Correct answer: Risk remaining after risk treatment measures have been applied
Residual risk is the level of risk that remains after the organization has implemented its chosen risk treatment controls.
Question 4: In a risk matrix, if a threat has HIGH likelihood but LOW impact, the overall risk level is typically classified as:
- Critical
- High
- Medium (Correct answer)
- Low
Correct answer: Medium
A high-likelihood, low-impact risk generally results in a medium overall risk rating when combined in a standard risk matrix.
Question 5: Which of the following is an example of a vulnerability rather than a threat?
- A disgruntled employee
- Unpatched operating system software (Correct answer)
- A ransomware attack
- A power outage
Correct answer: Unpatched operating system software
An unpatched operating system is a weakness (vulnerability) that could be exploited by a threat such as malware.
Question 6: According to ISO/IEC 27001, who has the ultimate responsibility for deciding how to treat identified information security risks?
- The external auditor
- The IT security team
- Risk owners (Correct answer)
- The certification body
Correct answer: Risk owners
Risk owners are accountable for approving risk treatment plans and accepting residual risks within their area of responsibility.
Question 7: Which element must be included in a risk treatment plan according to ISO/IEC 27001?
- A list of all accepted risks with no controls
- The actions to implement controls, responsible parties, and timelines (Correct answer)
- Only the financial cost of each control
- The organization's marketing strategy
Correct answer: The actions to implement controls, responsible parties, and timelines
A risk treatment plan must document the selected controls, who is responsible for implementation, and the expected completion dates.
Which ISO/IEC standard provides detailed guidance specifically on information security risk management to support ISO/IEC 27001?