The Concept of Risk in Information Security

5 minutes 5 Questions

In ISO/IEC 27001, risk is the core concept around which an Information Security Management System (ISMS) is built. ISO/IEC 27000, aligned with ISO 31000, defines risk as the 'effect of uncertainty on objectives.' This effect can be positive or negative, although information security risk usually fo…

Test mode:
More The Concept of Risk in Information Security questions
27 questions (total)