Risk Acceptance Criteria
Assign topic to the user
The organization can accept the risk, but as you know it is necessary to establish a criteria. What criteria? Please read this article Risk appetite and its influence over ISO 27001 implementation: https://advisera.com/27001academy/blog/2014/09/08/risk-appetite-influence-iso-27001-implementation/
And always you have to generate evidences, in this case for the approval of the Top Management you can use a record of a meeting.
Comment as guest or Sign in
Jan 12, 2016

