The incorrect statement is:
B. Information security risk cannot be accepted without being treated or during the process of risk treatment
This statement is NOT correct because according to ISO 27001, risk acceptance is one of the possible risk treatment options. Organizations may accept certain risks if the cost of mitigation is higher than the potential impact of the risk or if the risk is deemed to be at an acceptable level. Therefore, information security risks can be accepted without being treated, as part of the risk treatment process.
upvoted 1 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Everfaithful1
1 month, 2 weeks ago