Following an operational information security risk assessment under Clause 8.2, what documented information must the organization retain?
- A.The minutes of the management review that preceded the assessment
- B.A copy of every supplier contract referenced during the assessment
- C.Only the names of the personnel who attended the assessment workshop
- D.Documented information of the results of the information security risk assessments
Why D is correct
Clause 8.2 requires the organization to retain documented information of the results of the information security risk assessments. These records provide evidence that the assessment was performed and form the basis for risk treatment decisions.
Know someone studying for ISO 27001? Send them this one.