Guest
How to link risk assessment to Statement of Applicability
Many thanks for a very good webinar. One question came to mind after the webinar
once you have done your risk assessment and have a solid table listing your risk and their significance how do you then link that to the SOA and pick the controls you want?
Assign topic to the user
Answer: Once you identify all the risks, you have to select the ones that are not acceptable. For those unacceptable risks you have to select controls or other options for treating the risks - this is done through some kind of a risk treatment table. Once you select all the controls you want, then you start writing the Statement of Applicability.
Comment as guest or Sign in
Jan 12, 2016
Jan 12, 2016
Jan 12, 2016