QuestionQ14

Risk Management and Security Frameworks

Which standard defines the iterative risk management process shown below?

Question Image

  • A NIST CSF
  • B NIST 800-37
  • C ISO 27005
  • D FAIR
Explanation

ISO/IEC 27005 defines an information security risk management process comprising context establishment, risk assessment, risk treatment, risk acceptance, risk communication, and risk monitoring and review. Risk assessment includes risk identification, analysis, and evaluation. ISO: ISO/IEC 27005 risk-management process

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!