Risks registered is not effectives
Assign topic to the user
Some tips we can provide are:
- you can exclude not realistic risks from your assessment, in case you understand they will not add value to your assessment.
- for the registered issues, you can work on identifying potential root cases for them, and these root causes can be evaluated if they can be considered risks or not
- you can rewrite repeated risks in a way to consolidate them in fewer controls
- in fact, 140 risk for an organization of your size is an expected quantity. Please note that after the risk treatment option only part of them will need to receive additional treatment.
This article will provide you a further explanation about risk assessment:
- ISO 27001 Risk Assessment, Treatment, & Management: The Complete Guide https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/
These materials will also help you regarding risk assessment:
- The basics of risk assessment and treatment according to ISO 27001 [free webinar on demand] https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/
- Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-risk-management-in-plain-english/
Comment as guest or Sign in
Feb 22, 2022

