Under ISO 27005 retention criteria, RETAINING (accepting) a risk without adding controls is most clearly justified when:
- A.The risk is extremely high but no one wants to fund a control
- B.The risk's level is within the organization's defined risk acceptance criteria and treatment cost would exceed the benefit
- C.The risk is unknown and has never been assessed
- D.The risk owner is unavailable to make a decision
Why B is correct
Retention is appropriate when a risk already falls within acceptance criteria, or when the cost of further treatment outweighs the benefit. Retaining an unassessed or clearly excessive risk, or doing so by default, does not meet retention criteria.
Know someone studying for ISO 27001? Send them this one.