Expert Advice Community

Risk Assessment - change

  Quote
Nika Created:   Feb 11, 2021 Last commented:   Feb 12, 2021

Risk Assessment - change

Hi dear Team,

as we made the Risk Assessment initially, a couple of months ago, we've had some servers in one of the locations, which had high Risk levels. Now, we've moved them to the cloud, and don't have those risks anymore. Should we now perform the Risk Assessment again? If yes, should the previous version be saved as well?

Thank you!

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Feb 12, 2021

1. as we made the Risk Assessment initially, a couple of months ago, we've had some servers in one of the locations, which had high Risk levels. Now, we've moved them to the cloud, and don't have those risks anymore. Should we now perform the Risk Assessment again?

ISO 27001 requires a risk assessment to be performed at planned intervals, or when significant changes are proposed or occur, and normally servers change can be characterized as a significant change, so you must perform risk assessment again.

But please note that moving servers to the cloud may not mean that all related risks are eliminated. Some of them may have been only transferred. For example, if your servers are in a service provider´s cloud, the physical related risks are now with the provider (e.g., physical servers hosting your virtual server can fail), and to handle this risk you must ensure the existence of proper security clauses in the contract or service agreement with the provider.

For further information, see:

2. If yes, should the previous version be saved as well?

ISO 27001 requires results of risk assessment to be kept, so the previous version of risk assessment must be kept.

This article will provide you a further explanation about record management:

These materials will also help you regarding record management:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 11, 2021

Feb 12, 2021