ITPEC FE Morning October 2021 Question 40
ITPEC FE Morning October 2021 — Question 40 of 80
Level of Risk (ISO/IEC 27000) — definition from the ISMS vocabulary standard.
Per ISO/IEC 27000:2018, level of risk is the magnitude of a risk expressed as the combination of:
- Consequences — impact if the risk materializes
- Likelihood — probability of occurrence
In short: level of risk = consequences × likelihood
Why not others:
- (b) Risk criteria — terms of reference for evaluating significance
- (c) Risk prioritization — the order in which risks are handled
- (d) Vulnerability — a weakness that can be exploited by threats
Key rule: ISO 27000 risk terms to remember:
- Risk = effect of uncertainty on objectives
- Level of risk = consequences × likelihood
- Risk criteria = benchmarks for evaluating risk significance
- Vulnerability = exploitable weakness
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.