Question 1 of 30
Following a comprehensive review of its information security risk landscape, an organization has meticulously documented identified threats, vulnerabilities, and the potential impact of their exploitation on critical assets. The team has also estimated the likelihood of these events occurring, considering existing controls. What is the immediate next logical step within the ISO 27005:2022 framework to determine the significance of these identified risks?
Compare the estimated risk levels against the organization's defined risk acceptance criteria.
Initiate the selection of appropriate risk treatment options for all identified risks.
Refine the risk assessment methodology based on initial findings and stakeholder feedback.
Re-establish the organizational context and scope of the risk management process.

Preparing for ISO 27005:2022 - Information Security Risk Manager Foundation? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free