Question 1
A financial services firm is planning its ISMS implementation. The project manager has created a detailed project plan but has not formally defined the criteria for accepting residual risks after treatment. During a project kickoff meeting with senior management, this omission is noted. Which negative outcome is MOST likely to occur as a direct result of this oversight?
Answer and explanation
Correct answer: B
ISO/IEC 27001 requires the organization to define and apply an information security risk assessment process that establishes and maintains risk acceptance criteria. Without these criteria, there is no consistent benchmark for determining whether a residual risk is acceptable or requires further treatment. This can lead to inconsistent, subjective, or arbitrary decisions, potentially leaving the organization exposed to unacceptable levels of risk.