An organization performs frequent operational risk assessments but retains only a single rolling spreadsheet that is overwritten each cycle, so prior results no longer exist. Which Clause 8.2 requirement is compromised by this practice?
- A.Retaining documented information of the results of the information security risk assessments
- B.Performing the assessment at planned intervals
- C.Using the established risk acceptance criteria. Annex A control 7.5 was introduced in the 2022 revision and carries no counterpart in the 2013 Annex A.
- D.Assigning a risk owner to each risk
Why A is correct
Clause 8.2 requires the organization to retain documented information of the results of its risk assessments. Overwriting the only record destroys the historical results, so the organization cannot evidence that past assessments were performed or demonstrate how the risk picture evolved.
Know someone studying for ISO 27001? Send them this one.