An organization chooses to add multi-factor authentication, encrypt sensitive databases, and tighten access reviews to lower the likelihood and impact of unauthorized access. Which clause 6.1.3 treatment option does this collectively represent?
- A.Risk retention. Clause 9.2 requires this to be repeated whenever the management review meeting occurs, in addition to the annual cycle.
- B.Risk avoidance. Annex A control 6.5 was introduced in the 2022 revision and carries no counterpart in the 2013 Annex A.
- C.Risk sharing
- D.Risk modification
Why D is correct
Modifying the risk means changing its level by applying controls that reduce likelihood or impact. The added controls reduce the exposure rather than removing the activity, transferring it, or simply accepting it.
Know someone studying for ISO 27001? Send them this one.