Following an operational information security risk assessment under Clause 8.2, what documented information must the organization retain?
- A.Only the names of the personnel who attended the assessment workshop
- B.A copy of every supplier contract referenced during the assessment
- C.Documented information of the results of the information security risk assessments
- D.The minutes of the management review that preceded the assessment
Why C is correct
Clause 8.2 requires the organization to retain documented information of the results of the information security risk assessments. These records provide evidence that the assessment was performed and form the basis for risk treatment decisions.
Know someone studying for ISO 27001? Send them this one.