PECB Lead Implementer (ISO/IEC 27001) — Question 30

Based on scenario 4, the fact that TradeB defined the level of risk based on three nonnumerical categories indicates that:

Answer options

Correct answer: A

Explanation

The correct answer is A because qualitative criteria involve non-numerical assessments, which aligns with the use of non-numerical categories. Options B and C suggest a numerical or formulaic approach, which contradicts the scenario's emphasis on non-numerical categories.