>_ CYBERVERSE.AI

GRC interview question

Walk me through how you would conduct an ISO 27001 risk assessment.

What interviewers are really testing

A strong answer framework

  1. Define scope and risk acceptance criteria
  2. Build the asset inventory with owners
  3. Identify threats and vulnerabilities per asset
  4. Score likelihood x impact
  5. Choose treatment: mitigate, transfer, avoid, accept
  6. Record in the risk register and map controls to the SoA

Follow-ups you should be ready for

Reading answers is not the same as defending them.
Practice this question live with an AI interviewer that scores you out of 100.

Practice this question free at CyberVerse AI →

More real GRC interview questions