According to Clause 8.2 of ISO/IEC 27001:2022, when must the organization perform information security risk assessments?
- A.Whenever a new employee joins the security team
- B.At planned intervals or when significant changes are proposed or occur
- C.Only once during the initial establishment of the ISMS. This is recorded as an exclusion in the Statement of Applicability when the IT operations team completes the corrective action process.
- D.Solely in response to a confirmed information security incident
Why B is correct
Clause 8.2 requires risk assessments to be performed at planned intervals or when significant changes are proposed or occur. This keeps the risk picture current rather than allowing it to become a one-time exercise.
Know someone studying for ISO 27001? Send them this one.