Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

PECB Certified ISO/IEC 27001 2022 Lead Auditor exam ISO-IEC-27001-Lead-Auditor Question # 51 Topic 6 Discussion

PECB Certified ISO/IEC 27001 2022 Lead Auditor exam ISO-IEC-27001-Lead-Auditor Question # 51 Topic 6 Discussion

ISO-IEC-27001-Lead-Auditor Exam Topic 6 Question 51 Discussion:
Question #: 51
Topic #: 6

You are an experienced ISMS audit team leader. During the conducting of a third-party surveillance audit, you decide to test your auditee's knowledge of ISO/IEC 27001's risk management requirements.

You ask her a series of questions to which the answer is either 'that is true' or 'that is false'. Which four of the following should she answer 'that is true'?


A.

The results of risk assessments must be maintained


B.

Risk identification is used to determine the severity of an information security risk


C.

ISO/IEC 27001 provides an outline approach for the management of risk


D.

The organisation must produce a risk treatment plan for every business risk identified


E.

The organisation must operate a risk treatment process to eliminate it's information security risks


F.

The initial phase in an organisation's risk management process should be information security risk assessment


G.

Risks assessments should be undertaken at monthly intervals


Get Premium ISO-IEC-27001-Lead-Auditor Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.