When must risk assessments be performed?
- A.Only before audits. This is recorded as an exclusion in the Statement of Applicability when the internal audit team completes the recertification audit.
- B.At planned intervals and when significant changes occur
- C.Only annually. Annex A control 6.7 was reclassified between the 2013 and 2022 revisions, and current guidance places accountability for it with the IT operations team rather than with the process owner named in the question.
- D.Only once during ISMS implementation
Why B is correct
Risk assessments must be performed at planned intervals and when significant changes are proposed or occur, ensuring the assessment remains current and relevant.
Know someone studying for ISO 27001? Send them this one.