Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27005-Risk-Manager Exam - Topic 3 Question 29 Discussion

Scenario 1The risk assessment process was led by Henry, Bontton's risk manager. The first step that Henry took was identifying the company's assets. Afterward, Henry created various potential incident scenarios. One of the main concerns regarding the use of the application was the possibility of being targeted by cyber attackers, as a great number of organizations were experiencing cyberattacks during that time. After analyzing the identified risks, Henry evaluated them and concluded that new controls must be implemented if the company wants to use the application. Among others, he stated that training should be provided to personnel regarding the use of the application and that awareness sessions should be conducted regarding the importance of protecting customers' personal data.Lastly, Henry communicated the risk assessment results to the top management. They decided that the application will be used only after treating the identified risks.Based on scenario 1, Bontton used ISO/IEC 27005 to ensure effective implementation of all ISO/IEC 27001 requirements. Is this appropriate?
C) No, ISO/IEC 27005 does not contain direct guidance on the implementation of all requirements given in ISO/IEC 27001
A) Yes, ISO/IEC 27005 provides direct guidance on the implementation of the requirements given in ISO/IEC 27001
B) Yes, ISO/IEC 27005 provides a number of methodologies that can be used under the risk management framework for implementing all requirements given in ISO/IEC 27001

PECB ISO-IEC-27005-Risk-Manager Exam - Topic 3 Question 29 Discussion

Actual exam question for PECB's ISO-IEC-27005-Risk-Manager exam
Question #: 29
Topic #: 3
[All ISO-IEC-27005-Risk-Manager Questions]

Scenario 1

The risk assessment process was led by Henry, Bontton's risk manager. The first step that Henry took was identifying the company's assets. Afterward, Henry created various potential incident scenarios. One of the main concerns regarding the use of the application was the possibility of being targeted by cyber attackers, as a great number of organizations were experiencing cyberattacks during that time. After analyzing the identified risks, Henry evaluated them and concluded that new controls must be implemented if the company wants to use the application. Among others, he stated that training should be provided to personnel regarding the use of the application and that awareness sessions should be conducted regarding the importance of protecting customers' personal data.

Lastly, Henry communicated the risk assessment results to the top management. They decided that the application will be used only after treating the identified risks.

Based on scenario 1, Bontton used ISO/IEC 27005 to ensure effective implementation of all ISO/IEC 27001 requirements. Is this appropriate?

Show Suggested Answer Hide Answer
Suggested Answer: C

ISO/IEC 27005 is an international standard specifically focused on providing guidelines for information security risk management within the context of an organization's overall Information Security Management System (ISMS). It does not provide direct guidance on implementing the specific requirements of ISO/IEC 27001, which is a standard for establishing, implementing, maintaining, and continually improving an ISMS. Instead, ISO/IEC 27005 provides a framework for managing risks that could affect the confidentiality, integrity, and availability of information assets. Therefore, while ISO/IEC 27005 supports the risk management process that is crucial for compliance with ISO/IEC 27001, it does not contain specific guidelines or methodologies for implementing all the requirements of ISO/IEC 27001. This makes option C the correct answer.


ISO/IEC 27005:2018, 'Information Security Risk Management,' which emphasizes risk management guidance rather than direct implementation of ISO/IEC 27001 requirements.

ISO/IEC 27001:2013, Clause 6.1.2, 'Information Security Risk Assessment,' where risk assessment and treatment options are outlined but not in a prescriptive manner found in ISO/IEC 27005.

Contribute your Thoughts:

0/2000 characters
Ivory
7 hours ago
I agree, it provides solid methodologies for implementation.
upvoted 0 times
...
Denna
5 days ago
Not sure if it covers everything in ISO/IEC 27001 though.
upvoted 0 times
...
Leatha
11 days ago
ISO/IEC 27005 is definitely useful for risk management!
upvoted 0 times
...
Francoise
16 days ago
I recall discussing how ISO/IEC 27005 complements ISO/IEC 27001 but doesn’t directly implement all its requirements. I think option C makes sense based on that.
upvoted 0 times
...
Ashlyn
2 months ago
I’m not entirely sure, but I feel like ISO/IEC 27005 does help with understanding risk assessment, which might support ISO/IEC 27001. Maybe option A is the way to go?
upvoted 0 times
...
Aracelis
2 months ago
I think I saw a practice question where ISO/IEC 27005 was mentioned as providing methodologies for risk management. That makes me think option B could be correct.
upvoted 0 times
...
Kristin
2 months ago
I remember reading that ISO/IEC 27005 is more about risk management than directly implementing all ISO/IEC 27001 requirements. So, I’m leaning towards option C.
upvoted 0 times
...

Save Cancel