Information Security Risk Treatment and Risk Owners

5 minutes 5 Questions

Information security risk treatment is defined in ISO/IEC 27001 clause 6.1.3 and implemented under clause 8.3. After risks are identified, analysed and evaluated in the risk assessment (clause 6.1.2), the organization must define and apply a risk treatment process. This involves selecting appropria…

Test mode:
More Information Security Risk Treatment and Risk Owners questions
16 questions (total)