Which action is a required response to an identified residual risk?
Clause 6.1.3 (e) specifies:
''The organization shall obtain risk owners' approval of the information security risk treatment plan and acceptance of the residual information security risks.''
This confirms that residual risks --- those remaining after risk treatment --- must be reviewed and formally accepted by the designated risk owner. Option A is incorrect; awareness training is not a default control for all residual risks. Option B misrepresents leadership responsibility; top management ensures processes exist, but risk owners formally approve residual risk. Option D (avoiding risk) is a treatment option, not the mandated requirement for residual risks.
Thus, the required response is C: Review and acceptance by the risk owner.
Chaya
3 months agoCraig
4 months agoDelbert
4 months agoChantay
4 months agoJohnetta
4 months agoChaya
5 months agoDelbert
5 months agoCraig
5 months agoCeleste
5 months agoTalia
6 months agoFlorinda
6 months agoDustin
6 months agoLoreen
6 months agoAudrie
6 months agoCandida
6 months agoLizbeth
7 months agoValentine
7 months agoChantay
7 months agoJohnetta
7 months agoJohnetta
7 months agoTyisha
8 months agoNadine
8 months agoLashaunda
8 months agoTrinidad
9 months agoMatt
9 months agoLaila
9 months agoLevi
9 months agoMozelle
9 months agoHyun
9 months agoKallie
3 months agoMaynard
3 months agoReid
3 months agoFelicitas
8 months ago