4.3 A detailed look at ISO31000:2018 Flashcards

1
Q

In what year was ISO 31000 first published?

A

2009

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

The objective of ISO31000 is to provide a set of i___________ recognised principles and guidance on the practice of risk management in organisations. These principles and guidance may be used to help improve the d______ and implementation of a risk management framework.

A

internationally

design

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why does ISO 31000 not suggest a uniform approach to risk management?

A

It recognizes that organizations must design and implement a framework appropriate to the nature, scale and complexity of the organization,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

ISO31000 covers:

  • d________ of key terms
  • importance of managing the opportunities and threats from r_____-
  • basic p_________ of risk management
  • design, implementation and r________ of a risk management framework
  • key components of an effective risk management process
A

definitions
risks
principles
review

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the three central topics of the 2018 ISO31000 standard?

A

1 Principles for risk management
2 Core elements of an effective risk management framework
3 The risk management process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The core principle of the 2018 ISO31000 standard is that risk management activity should protect…. what?

A

Value

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

In terms of the risk management process, ISO31000 covers three elements:
1 Establishing the c________
2 Risk a_____________
3 Risk t___________

A

context
assessment
treatment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is meant by “context” in risk management?

A

Understanding the internal and external drivers affecting risk exposure, and understanding the types of risk that exist.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is meant by risk assessment?

A

Identifying, analysing and evaluation exposure to all sources of risk to an organisation’s objectives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

“Risk treatment” is another term for what, meaning ensuring the level of risk exposure in managed?

A

Risk control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

The level of risk control within an organisation is influenced by its r_____ a__________

A

risk appetite

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is meant by “recording risks”?

A

Ensuring that identified risks are documented properly.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is meant by “risk reporting”?

A

Ensuring that organisation’s risk exposures and measures taken to control exposure are reported to decision makers and stakeholders.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

“Monitoring and review” of risk is about l______, i__________ and a________.

A

Learning, improving and adapting

How well did you know this?
1
Not at all
2
3
4
5
Perfectly