transition from ISO 27001 risk assessment (asset based) to ISO 31000 based risk assessment (context based)? please share the sample format?
Answer:
There is no requirement to use ISO 31000 risk assessment methodology in when implementing ISO 27001, both are different standards: ISO 27001 establishes requisites for a Information Security Management System, and ISO 31000 is a guideline for the risk management.
Anyway, ISO 27001:2013 not requires you to use a specific model based methodology, so if you want, in ISO 27001:2013 you can use an asset based methodology, or if you want, you can use a process based methodology, or any other.
It is important to say here that ISO 27005 is very similar to ISO 31000, but ISO 27005 is focused on risks related to information security (ISO 31000 is for any type of risks).
Finally, I am not sure what you mean with sample format, but we have a template for the methodology of the risk management (asset based), you can see a free version here clicking on Free Demo tab Risk Assessment and Risk Tr eatment Methodology : https://advisera.com/27001academy/documentation/Risk-Assessment-and-Risk-Treatment-Methodology/
You can also read these articles:
How to write ISO 27001 risk assessment methodology : https://advisera.com/27001academy/knowledgebase/write-iso-27001-risk-assessment-methodology/
What has changed in risk assessment in ISO 27001:2013 : https://advisera.com/27001academy/knowledgebase/what-has-changed-in-risk-assessment-in-iso-270012013/
ISO 31000 and ISO 27001 How are they related? : https://advisera.com/27001academy/blog/2014/03/31/iso-31000-and-iso-27001-how-are-they-related/
Comment as guest or Sign in
Jan 12, 2016