An organization wants to know which operational records it must retain after each cycle of its risk processes. Considering Clauses 8.2 and 8.3 together, which pair of records is mandatory?
- A.The names of attendees at the risk workshop and the meeting room booking
- B.The certification certificate and the auditor's CV
- C.The marketing plan and the annual report
- D.The results of the information security risk assessments and the results of the information security risk treatment
Why D is correct
Clause 8.2 requires retaining documented information of risk assessment results and Clause 8.3 requires retaining documented information of risk treatment results. Together these two record sets evidence the operational risk cycle and provide traceability from assessed risk to applied treatment.
Know someone studying for ISO 27001? Send them this one.