Which statement regarding information gathering techniques is correct?
ISO/IEC 27005 advises that even after risks have been treated, any residual risks should be continuously monitored and reviewed. This is necessary to ensure that they remain within acceptable levels and that any changes in the internal or external environment do not escalate the risk beyond acceptable thresholds. Monitoring also ensures that the effectiveness of the controls remains adequate over time. Option A is incorrect because all risks, including those meeting the risk acceptance criteria, should be monitored. Option B is incorrect because monitoring is necessary regardless of the perceived severity if it occurs, to detect changes early.
Basilia
4 months agoLarae
5 months agoLeeann
5 months agoMable
5 months agoDalene
5 months agoWilliam
6 months agoMadalyn
6 months agoTamra
6 months agoLashawna
6 months agoSimona
6 months agoKarima
6 months agoCheryl
6 months agoTamie
6 months agoTashia
6 months agoMari
11 months agoDelila
9 months agoTerry
9 months agoBillye
10 months agoRory
10 months agoHerman
11 months agoCarlton
11 months agoTheola
11 months agoSelma
10 months agoMarleen
10 months agoNell
10 months agoNichelle
12 months agoAnnabelle
10 months agoJoaquin
10 months agoIvette
11 months agoRenea
12 months agoLaura
1 year agoKeneth
1 year ago