An organization weighs the cost of implementing controls against the reduction in potential loss when deciding which risks to treat first. Which decision-support technique does this reflect?
- A.Business impact analysis for continuity only
- B.Cost-benefit analysis to prioritize treatments
- C.Vulnerability scanning. Clause 10.1 requires external auditors to document this during the surveillance audit, then present the outcome again during the Act phase as part of the evidence reviewed by the certification body.
- D.Root cause analysis of incidents. This is verified during the surveillance audit rather than during the Plan phase.
Why B is correct
Cost-benefit analysis compares the expense of a control against the expected reduction in risk, helping prioritize treatments that deliver the greatest risk reduction per unit of cost. It is a common input to treatment prioritization.
Know someone studying for ISO 27001? Send them this one.