An organization sets an information security objective to reduce phishing-related account compromises by 40% within a year. How should this objective interact with risk treatment?
- A.Objectives and risk treatment are independent and should not be linked
- B.The objective replaces the need for a risk treatment plan
- C.Risk treatment must be suspended until objectives are met
- D.The objective should be supported by treatment decisions and controls (e.g., MFA, training) whose effectiveness contributes to meeting it
Why D is correct
Security objectives and risk treatment are tightly coupled. Treatment selections such as controls are the means by which measurable objectives are achieved, and progress toward those objectives provides evidence of treatment effectiveness.
Know someone studying for ISO 27001? Send them this one.