Question 1 of 30
Cost-benefit analysis shows that implementing a highly detailed, quantitative risk assessment model with extensive data collection requirements would be significantly more expensive than initially budgeted, potentially diverting resources from essential control implementation. Given this, which risk assessment methodology approach best aligns with the principles of ISO 27001:2022 for an organization of moderate size and complexity?
A structured, iterative qualitative methodology that defines clear criteria for likelihood and impact, allowing for consistent scoring and prioritization of risks, and is supported by a defined process for evaluating existing controls.
A purely qualitative approach that relies on subjective expert judgment for all risk ratings without any defined scoring matrix or impact scales.
A complex, quantitative model that attempts to assign precise numerical values to all risk factors, even if it requires significant investment in specialized software and training beyond the initial budget.
A methodology that focuses exclusively on identifying potential threats without a systematic process for assessing their likelihood, impact, or the effectiveness of existing controls.

Preparing for ISO 27001 Lead Auditor? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free