Question 1 of 30
A multinational corporation is in the process of implementing an Information Security Management System (ISMS) based on ISO 27001. The organization has identified several risks associated with its information assets and is now evaluating the effectiveness of its risk treatment plan. The plan includes various controls from ISO 27002. If the organization has a risk appetite defined as a maximum acceptable risk level of 15% and the residual risk after implementing the controls is calculated to be 12%, what should the organization conclude about its risk treatment plan?
The risk treatment plan is effective as the residual risk is below the risk appetite.
The risk treatment plan is ineffective and requires immediate revision.
The organization should consider additional controls to further reduce the residual risk.
The organization can accept the residual risk without further action.

Preparing for CISCO 350-701 Implementing and Operating Cisco Security Core Technologies (SCOR)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free