Risk assessment results directly reflect information security performance because they show the current risk landscape, effectiveness of controls, and overall security posture. This is a specific input for management review under ISO/IEC 27001.
“Management review inputs shall include... results of risk assessment and status of risk treatment plan, which relate directly to information security performance.”
— ISO/IEC 27001:2022, Clause 9.3.2
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit