New Year Sale ! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GAQM Exam ISO-31000-CLA Topic 4 Question 5 Discussion

Actual exam question for GAQM's ISO-31000-CLA exam
Question #: 5
Topic #: 4
[All ISO-31000-CLA Questions]

Which step is the last part of the risk assessment process, which started with risk identification then moved to risk assessment, and finally risk evaluation?

Show Suggested Answer Hide Answer
Suggested Answer: A

the last step of the risk assessment process, which starts with risk identification, moves to risk assessment, and finally risk evaluation, is Risk evaluation.

Risk evaluation involves comparing the estimated level of risk against the risk criteria established during the risk assessment phase, to determine the significance of the risk and whether it is acceptable or not. This decision is made in consultation with stakeholders, who may provide additional context and information to inform the decision.

The American Society for Quality (ASQ) describes risk evaluation as 'the process of comparing an estimated risk against given risk criteria to determine the acceptability of the risk.' [1]

Similarly, ISO/IEC 27001:2013 (Information technology --- Security techniques --- Information security management systems --- Requirements) defines risk evaluation as 'the process of comparing the estimated risk against given risk criteria in order to determine the significance of the risk.' [2]


Contribute your Thoughts:

Irene
4 days ago
Haha, I bet the risk assessors are having a risky time with this one! But I'll go with C) Risk acceptance too.
upvoted 0 times
...
Evette
6 days ago
I'm going with C) Risk acceptance. It makes the most sense as the final step in the risk assessment workflow.
upvoted 0 times
...
Lashaunda
13 days ago
Definitely C) Risk acceptance. That's the logical conclusion of the risk assessment process.
upvoted 0 times
Lezlie
5 days ago
I agree, C) Risk acceptance is the last step in the risk assessment process.
upvoted 0 times
...
...
Kallie
1 months ago
I'm not sure, but I think it could also be risk acceptance because that's when you decide if the risk is worth taking.
upvoted 0 times
...
Marge
1 months ago
I agree with Sarah, risk evaluation makes sense as the final step.
upvoted 0 times
...
Lili
1 months ago
I think the answer is C) Risk acceptance. After identifying and assessing the risks, the final step is to determine which risks to accept and manage.
upvoted 0 times
Monte
6 days ago
Yes, it's crucial to have a clear plan for managing accepted risks.
upvoted 0 times
...
Sommer
20 days ago
I think it's important to carefully consider each risk before accepting it.
upvoted 0 times
...
Lyla
25 days ago
That makes sense, we need to decide which risks to accept.
upvoted 0 times
...
Dorcas
27 days ago
I agree, the last step is C) Risk acceptance.
upvoted 0 times
...
...
Sarah
1 months ago
I think the last step is risk evaluation.
upvoted 0 times
...

Save Cancel