Assets, Threats, Vulnerabilities and Risks

5 minutes 5 Questions

In ISO/IEC 27001, information security management is built on understanding how assets, threats, vulnerabilities and risks relate to each other. A Lead Auditor must understand these concepts to judge whether an organization's risk assessment and treatment process (clauses 6.1.2 and 6.1.3) is sound.…

Test mode:
More Assets, Threats, Vulnerabilities and Risks questions
28 questions (total)