New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27005-Risk-Manager Exam - Topic 3 Question 21 Discussion

Actual exam question for PECB's ISO-IEC-27005-Risk-Manager exam
Question #: 21
Topic #: 3
[All ISO-IEC-27005-Risk-Manager Questions]

Scenario 2: Travivve is a travel agency that operates in more than 100 countries. Headquartered in San Francisco, the US, the agency is known for its personalized vacation packages and travel services. Travivve aims to deliver reliable services that meet its clients' needs. Considering the impact of information security in its reputation, Travivve decided to implement an information security management system (ISMS) based on ISO/IEC 27001. In addition, they decided to establish and implement an information security risk management program. Based on the priority of specific departments in Travivve, the top management decided to initially apply the risk management process only in the Sales Management Department. The process would be applicable for other departments only when introducing new technology.

Travivve's top management wanted to make sure that the risk management program is established based on the industry best practices. Therefore, they created a team of three members that would be responsible for establishing and implementing it. One of the team members was Travivve's risk manager who was responsible for supervising the team and planning all risk management activities. In addition, the risk manager was responsible for monitoring the program and reporting the monitoring results to the top management.

Initially, the team decided to analyze the internal and external context of Travivve. As part of the process of understanding the organization and its context, the team identified key processes and activities. Then, the team identified the interested parties and their basic requirements and determined the status of compliance with these requirements. In addition, the team identified all the reference documents that applied to the defined scope of the risk management process, which mainly included the Annex A of ISO/IEC 27001 and the internal security rules established by Travivve. Lastly, the team analyzed both reference documents and justified a few noncompliances with those requirements.

The risk manager selected the information security risk management method which was aligned with other approaches used by the company to manage other risks. The team also communicated the risk management process to all interested parties through previously established communication mechanisms. In addition, they made sure to inform all interested parties about their roles and responsibilities regarding risk management. Travivve also decided to involve interested parties in its risk management activities since, according to the top management, this process required their active participation.

Lastly, Travivve's risk management team decided to conduct the initial information security risk assessment process. As such, the team established the criteria for performing the information security risk assessment which included the consequence criteria and likelihood criteria.

Did Travivve's risk management team identify the basic requirements of interested parties in accordance with the guidelines of ISO/IEC 27005? Refer to scenario 2.

Show Suggested Answer Hide Answer
Suggested Answer: C

According to ISO/IEC 27005, understanding the organization and its context, including the identification of interested parties and their requirements, is a critical part of the risk management process. The team at Travivve identified the interested parties and their basic requirements and determined the status of compliance with these requirements, which aligns with the guidelines provided by ISO/IEC 27005. This standard recommends that organizations should understand their context and stakeholders' requirements to effectively manage risks. Additionally, it is appropriate to evaluate compliance with requirements as part of the context analysis, rather than after implementing risk treatment options. Therefore, the team's approach was in accordance with ISO/IEC 27005, making option C the correct answer.


ISO/IEC 27005:2018, Clause 7, 'Context Establishment,' which outlines the importance of identifying the context, including the interested parties and their requirements, as a basis for risk management.

Contribute your Thoughts:

0/2000 characters
Elfriede
2 months ago
Yes, they followed ISO/IEC 27005 guidelines, good move!
upvoted 0 times
...
Julio
2 months ago
Wait, did they really analyze all interested parties? Sounds a bit rushed.
upvoted 0 times
...
Quentin
2 months ago
They operate in over 100 countries, that's impressive!
upvoted 0 times
...
Denna
3 months ago
I think they should've looked at compliance before defining requirements.
upvoted 0 times
...
Ronald
3 months ago
Totally agree, but focusing on just one department seems risky.
upvoted 0 times
...
Quentin
3 months ago
I feel like they might have missed something by only using internal rules, but I can't recall the exact details from the study materials.
upvoted 0 times
...
Mary
3 months ago
I practiced a similar question where the focus was on compliance with requirements, and it seems like they followed the guidelines well.
upvoted 0 times
...
Charisse
4 months ago
I'm not entirely sure, but I thought the compliance status should be checked after risk treatment options are in place.
upvoted 0 times
...
Mozell
4 months ago
I remember that ISO/IEC 27005 emphasizes understanding the needs of interested parties, so I think they did identify those requirements correctly.
upvoted 0 times
...
Cyril
4 months ago
I feel confident that the team followed the recommended approach from ISO/IEC 27005. The question is asking if they identified the basic requirements and determined compliance status, which the scenario indicates they did.
upvoted 0 times
...
Antonio
4 months ago
The scenario gives a lot of details, so I'm going to carefully review each step the team took to make sure I understand the process they followed.
upvoted 0 times
...
Cortney
4 months ago
Based on the information provided, it seems the team did identify the basic requirements of the interested parties and determine the status of compliance, which aligns with the guidelines in ISO/IEC 27005. So I think the answer is C.
upvoted 0 times
...
Rashad
5 months ago
I'm a bit confused about the requirements for the interested parties. Do we need to define their requirements, or just determine the status of compliance with them?
upvoted 0 times
...
Melodie
5 months ago
This question seems straightforward. The key is to focus on the steps the risk management team took, as outlined in the scenario.
upvoted 0 times
...
Salena
8 months ago
You know, with all these security standards, I bet the Travivve team could write a thriller novel about the challenges of implementing an ISMS. The suspense would be off the charts!
upvoted 0 times
Truman
7 months ago
B) No, the team should use only the organization's internal security rules to determine the status of compliance with the basic requirements of interested parties
upvoted 0 times
...
Gerri
8 months ago
A) No, the team should define the basic requirements of interested parties, but it should determine status of compliance with the requirements after implementing the risk treatment options
upvoted 0 times
...
...
Nicholle
8 months ago
Haha, I wonder if Travivve's risk manager has a superpower to keep track of all the acronyms and standards. ISO/IEC 27001 and 27005 are a mouthful!
upvoted 0 times
Garry
7 months ago
Haha, it must be challenging to keep track of all those acronyms and standards!
upvoted 0 times
...
Kenneth
7 months ago
C) Yes, the team identified the basic requirements of interested parties and determined the status of compliance with those requirements as recommended by ISO/IEC 27005
upvoted 0 times
...
Isadora
8 months ago
B) No, the team should use only the organization's internal security rules to determine the status of compliance with the basic requirements of interested parties
upvoted 0 times
...
Colette
8 months ago
A) No, the team should define the basic requirements of interested parties, but it should determine status of compliance with the requirements after implementing the risk treatment options
upvoted 0 times
...
...
Janet
8 months ago
I agree, the team seems to have covered all the necessary steps to set the foundation for the risk management program. Involving the interested parties is crucial for success.
upvoted 0 times
...
Denny
9 months ago
The team definitely followed the ISO/IEC 27005 guidelines by identifying the basic requirements of interested parties and determining their compliance status. That's a solid approach to understanding the context before diving into the risk assessment.
upvoted 0 times
Vi
8 months ago
That's a solid approach to understanding the context before diving into the risk assessment.
upvoted 0 times
...
Ocie
8 months ago
C) Yes, the team identified the basic requirements of interested parties and determined the status of compliance with those requirements as recommended by ISO/IEC 27005
upvoted 0 times
...
Leonora
8 months ago
A) No, the team should define the basic requirements of interested parties, but it should determine status of compliance with the requirements after implementing the risk treatment options
upvoted 0 times
...
Anna
9 months ago
C) Yes, the team identified the basic requirements of interested parties and determined the status of compliance with those requirements as recommended by ISO/IEC 27005
upvoted 0 times
...
Judy
9 months ago
A) No, the team should define the basic requirements of interested parties, but it should determine status of compliance with the requirements after implementing the risk treatment options
upvoted 0 times
...
...
Herschel
9 months ago
So, you think the answer is C then?
upvoted 0 times
...
Melda
9 months ago
I believe the team did identify the basic requirements and checked compliance with them.
upvoted 0 times
...
Caprice
10 months ago
I agree with you, Herschel. It's important to know what the interested parties need.
upvoted 0 times
...
Herschel
10 months ago
I think the team should define the basic requirements of interested parties first.
upvoted 0 times
...

Save Cancel