What is a threat in ISO 27001 risk assessment?
- A.A confirmed security incident. Annex A control 6.8 was reclassified between the 2013 and 2022 revisions, and current guidance places accountability for it with the information security committee rather than with the process owner named in the question.
- B.A vulnerability
- C.A potential cause of an unwanted incident that may result in harm
- D.A security control. This is delegated to the ISMS manager under Clause 7.2, separate from the certification decision.
Why C is correct
A threat is a potential cause of an unwanted incident, which may result in harm to an organization's information or information systems.
Know someone studying for ISO 27001? Send them this one.