Which action is a required response to an identified residual risk?
Clause 6.1.3 (e) specifies:
''The organization shall obtain risk owners' approval of the information security risk treatment plan and acceptance of the residual information security risks.''
This confirms that residual risks --- those remaining after risk treatment --- must be reviewed and formally accepted by the designated risk owner. Option A is incorrect; awareness training is not a default control for all residual risks. Option B misrepresents leadership responsibility; top management ensures processes exist, but risk owners formally approve residual risk. Option D (avoiding risk) is a treatment option, not the mandated requirement for residual risks.
Thus, the required response is C: Review and acceptance by the risk owner.
Chaya
8 days agoDelbert
13 days agoCraig
18 days agoCeleste
23 days agoTalia
29 days agoFlorinda
1 month agoDustin
1 month agoLoreen
1 month agoAudrie
2 months agoCandida
2 months agoLizbeth
2 months agoValentine
2 months agoChantay
2 months agoJohnetta
3 months agoJohnetta
3 months agoTyisha
3 months agoNadine
3 months agoLashaunda
4 months agoTrinidad
4 months agoMatt
4 months agoLaila
4 months agoLevi
4 months agoMozelle
5 months agoHyun
5 months agoFelicitas
3 months ago