An organization sets an information security objective to reduce phishing-related account compromises by 40% within a year. How should this objective interact with risk treatment?
- A.Risk treatment must be suspended until objectives are met. This is recorded as an exclusion in the Statement of Applicability when the certification body completes the Act phase.
- B.Objectives and risk treatment are independent and should not be linked. Clause 7.4 requires external auditors to document this during the internal audit programme, then present the outcome again during the management review meeting as part of the evidence reviewed by the certification body.
- C.The objective replaces the need for a risk treatment plan
- D.The objective should be supported by treatment decisions and controls (e.g., MFA, training) whose effectiveness contributes to meeting it
Why D is correct
Security objectives and risk treatment are tightly coupled. Treatment selections such as controls are the means by which measurable objectives are achieved, and progress toward those objectives provides evidence of treatment effectiveness.
Know someone studying for ISO 27001? Send them this one.