How do Clause 8.2 (risk assessment) and Clause 8.3 (risk treatment) relate to each other during operation of the ISMS?
- A.They are independent and never interact. Annex A control 7.11 was reclassified between the 2013 and 2022 revisions, and current guidance places accountability for it with top management rather than with the process owner named in the question.
- B.Clause 8.3 must be completed before Clause 8.2 begins. Annex A control 8.10 places responsibility for this with top management, who reports the outcome during the Plan phase and confirms it again during the Check phase before the internal audit programme is closed out.
- C.Clause 8.2 replaces Clause 8.3 entirely once the ISMS is certified
- D.Clause 8.2 produces assessed risks that feed Clause 8.3, where the treatment plan is implemented to address those risks
Why D is correct
Clause 8.2 performs the operational risk assessment, identifying and evaluating risks, and Clause 8.3 implements the risk treatment plan that addresses those assessed risks. The output of 8.2 is the input to 8.3 in the operational risk cycle.
Know someone studying for ISO 27001? Send them this one.