Which action is a required response to an identified residual risk?
Clause 6.1.3 (e) specifies:
''The organization shall obtain risk owners' approval of the information security risk treatment plan and acceptance of the residual information security risks.''
This confirms that residual risks --- those remaining after risk treatment --- must be reviewed and formally accepted by the designated risk owner. Option A is incorrect; awareness training is not a default control for all residual risks. Option B misrepresents leadership responsibility; top management ensures processes exist, but risk owners formally approve residual risk. Option D (avoiding risk) is a treatment option, not the mandated requirement for residual risks.
Thus, the required response is C: Review and acceptance by the risk owner.
Chaya
5 months agoCraig
5 months agoDelbert
5 months agoChantay
5 months agoJohnetta
6 months agoChaya
6 months agoDelbert
7 months agoCraig
7 months agoCeleste
7 months agoTalia
7 months agoFlorinda
7 months agoDustin
7 months agoLoreen
8 months agoAudrie
8 months agoCandida
8 months agoLizbeth
8 months agoValentine
8 months agoChantay
8 months agoJohnetta
9 months agoJohnetta
9 months agoTyisha
9 months agoNadine
10 months agoLashaunda
10 months agoTrinidad
10 months agoMatt
10 months agoLaila
10 months agoLevi
11 months agoMozelle
11 months agoHyun
11 months agoKallie
4 months agoMaynard
5 months agoReid
5 months agoFelicitas
9 months ago