An organization performs frequent operational risk assessments but retains only a single rolling spreadsheet that is overwritten each cycle, so prior results no longer exist. Which Clause 8.2 requirement is compromised by this practice?
- A.Performing the assessment at planned intervals
- B.Retaining documented information of the results of the information security risk assessments
- C.Using the established risk acceptance criteria
- D.Assigning a risk owner to each risk
Why B is correct
Clause 8.2 requires the organization to retain documented information of the results of its risk assessments. Overwriting the only record destroys the historical results, so the organization cannot evidence that past assessments were performed or demonstrate how the risk picture evolved.
Know someone studying for ISO 27001? Send them this one.