GAQM ISO 27001:2013 ISMS - Certified Lead Auditor ISO-ISMS-LA Question # 12 Topic 2 Discussion

GAQM ISO 27001:2013 ISMS - Certified Lead Auditor ISO-ISMS-LA Question # 12 Topic 2 Discussion

ISO-ISMS-LA Exam Topic 2 Question 12 Discussion:
Question #: 12
Topic #: 2

A couple of years ago you started your company which has now grown from 1 to 20 employees. Your company’s information is worth more and more and gone are the days when you could keep control yourself. You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis. 

What is a qualitative risk analysis? 


A.

This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage. 


B.

This analysis is based on scenarios and situations and produces a subjective view of the possible threats.


Get Premium ISO-ISMS-LA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.