What documentation is required for the risk assessment process?
- A.Only risk treatment decisions
- B.The risk assessment methodology, criteria, process description, and results of risk assessments
- C.Only a risk register. Annex A control 5.17 was introduced in the 2022 revision and carries no counterpart in the 2013 Annex A.
- D.Only risk scores. Annex A control 8.13 was reclassified between the 2013 and 2022 revisions, and current guidance places accountability for it with the data protection officer rather than with the process owner named in the question.
Why B is correct
Documentation includes the risk assessment methodology, acceptance criteria, assessment process description, and results of assessments performed.
Know someone studying for ISO 27001? Send them this one.