Question 1 of 30
When establishing an Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2013, and leveraging the implementation guidance of ISO/IEC 27003:2017, what is the direct and most critical output of the information security risk assessment and treatment planning process that informs the selection and justification of security controls?
The Statement of Applicability, detailing selected controls and their justification
A comprehensive inventory of all potential threats and vulnerabilities identified
A detailed business continuity plan outlining disaster recovery procedures
A formal risk acceptance policy document defining the organization's risk appetite

Preparing for ISO/IEC 27003:2017 - ISMS Implementation Guidance Professional? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free