Question 1 of 30
In the context of ISO/IEC standards, a multinational corporation is evaluating its compliance with the ISO/IEC 27001 standard for information security management systems (ISMS). The company has implemented various controls and is now assessing the effectiveness of these controls. If the organization identifies that the risk assessment process is not adequately identifying potential threats, which of the following actions should be prioritized to align with the ISO/IEC 27001 requirements?
Conduct a comprehensive review of the risk assessment methodology and update it to include a broader range of potential threats and vulnerabilities.
Increase the number of security controls without assessing their relevance to the identified risks.
Focus solely on implementing technical controls while neglecting administrative and physical controls.
Limit the risk assessment to only the most critical assets, ignoring less critical ones.

Preparing for CISCO 400-007 Cisco Certified Design Expert? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free