Which action is a required response to an identified residual risk?
Clause 6.1.3 (e) specifies:
''The organization shall obtain risk owners' approval of the information security risk treatment plan and acceptance of the residual information security risks.''
This confirms that residual risks --- those remaining after risk treatment --- must be reviewed and formally accepted by the designated risk owner. Option A is incorrect; awareness training is not a default control for all residual risks. Option B misrepresents leadership responsibility; top management ensures processes exist, but risk owners formally approve residual risk. Option D (avoiding risk) is a treatment option, not the mandated requirement for residual risks.
Thus, the required response is C: Review and acceptance by the risk owner.
Chaya
2 months agoCraig
2 months agoDelbert
2 months agoChantay
2 months agoJohnetta
3 months agoChaya
3 months agoDelbert
4 months agoCraig
4 months agoCeleste
4 months agoTalia
4 months agoFlorinda
4 months agoDustin
4 months agoLoreen
5 months agoAudrie
5 months agoCandida
5 months agoLizbeth
5 months agoValentine
5 months agoChantay
5 months agoJohnetta
6 months agoJohnetta
6 months agoTyisha
6 months agoNadine
7 months agoLashaunda
7 months agoTrinidad
7 months agoMatt
7 months agoLaila
7 months agoLevi
8 months agoMozelle
8 months agoHyun
8 months agoKallie
1 month agoMaynard
2 months agoReid
2 months agoFelicitas
6 months ago