Question 1 of 30
Consider an organization that has completed its information security risk assessment and identified several high-severity risks related to unauthorized access to sensitive customer data. The risk treatment plan has been approved, with the decision to mitigate these risks by implementing stronger access controls and data encryption. Which document, as mandated by ISO 27001:2022, would most directly reflect and provide justification for the selection of these specific controls as a response to the identified risks?
The Statement of Applicability (SoA)
The Information Security Policy
The Risk Treatment Plan (RTP)
The Information Security Objectives

Preparing for ISO 27001:2022 - Statement of Applicability (SoA) Development Professional? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free