CRISC - Risk Assessment - Section 2.5

Select risk assessment concepts, standards and frameworks appropriate to the organisation.

Compare risk assessment standards and frameworks - including ISO 31000 and NIST risk frameworks - across their scope, terminology, and assessment methods. Select the approach that best fits the organisation's industry, regulatory context, and risk management maturity.

Risk assessment standardsISO 31000NIST risk frameworksAssessment methods

Practice question for this objective

Free sampleRisk Assessmentmedium

A multinational retailer already certified to ISO 27001 wants to adopt a risk assessment standard that integrates cleanly with its existing information security management system without introducing a conflicting risk vocabulary. Which standard is the most appropriate choice?

  • AISO 27005, because it provides information security risk guidance designed to support the ISO 27001 management system already in place. Correct
  • BFAIR, because it supplies a taxonomy for quantifying cyber loss that can replace the existing management system risk process.
  • COCTAVE Allegro, because it offers a self-directed workshop method that operates independently of any existing management system.
  • DPCI DSS, because it defines a prescriptive control baseline that the retailer can substitute for its current risk process.
Select ISO 27005 as the risk assessment standard that aligns with and supports an existing ISO 27001 information security management system. ISO 27005 was written specifically to provide information security risk management guidance consistent with ISO 27001, so adopting it reuses the same terminology and process rather than imposing a competing risk vocabulary.

Why A is correct: ISO 27005 is purpose-built to support an ISO 27001 information security management system, so its terms and process align with the retailer's existing certification.

Why B is wrong: It is tempting as a quantification model, but positioning it to replace the existing process introduces the very vocabulary conflict the retailer wants to avoid.

Why C is wrong: It is plausible as an established assessment method, yet its self-directed approach sits apart from ISO and does not integrate with the certified management system.

Why D is wrong: It is attractive given the retail payment context, but PCI DSS is a control mandate for card data, not a risk assessment standard that integrates with ISO 27001.

See more CRISC practice questions, answers explained.

More in this domain

Back to all Risk Assessment objectives, or the CRISC cert hub.

Examworthy is not affiliated with or endorsed by ISACA. Original, blueprint-aligned practice material only.