Here are all the actual test exam dumps for IT exams. Most people prepare for the actual exams with our test dumps to pass their exams. So it's critical to choose and actual test pdf to succeed.

Exam ISO-IEC-27001-Lead-Auditor Topic 5 Question 291 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 291
Topic #: 5
Question:
A marketing agency has developed its risk assessment approach as part of the ISMS implementation. Is this acceptable?

Suggested Answer: A Vote an answer

Comprehensive and Detailed In-Depth Explanation:
ISO/IEC 27001 does not prescribe a specific risk assessment methodology but instead provides general requirements for risk assessment. Organizations are free to develop their own risk assessment methods, as long as they:
* Identify risks and impacts on information security.
* Define risk criteria for evaluating risks.
* Implement risk treatment plans based on the organization's context.
A). Correct Answer:
* ISO/IEC 27001 Clause 6.1.2 (Information Security Risk Assessment) states that organizations may define their own risk assessment methodology.
* This approach must be systematic, measurable, and aligned with business objectives.
B). Incorrect:
* Organizations are not required to use a recognized methodology like OCTAVE, MEHARI, or EBIOS, as long as their approach meets ISO requirements.
C). Incorrect:
* ISO/IEC 27001 does not mandate a specific risk assessment method, only that a consistent and structured approach is used.
Relevant Standard Reference:
* ISO/IEC 27001:2022 Clause 6.1.2 (Information Security Risk Assessment Process)

by Montague at Mar 06, 2026, 04:20 PM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.