RARTP vs NCPA
Assign topic to the user
The purpose of risk assessment / risk treatment is to prevent incidents from happening, while the purpose of corrective actions is to prevent nonconformities to re-occur.
Security incidents are when the confidentiality, integrity and availability of your information is endangered (e.g., hacker attack); nonconformities are when some of your internal rules have not been complied with (e.g., not performing the backup according to the Backup procedure).
These articles will help you:
- How to handle incidents according to ISO 27001 A.16 https://advisera.com/27001academy/blog/2015/10/26/how-to-handle-incidents-according-to-iso-27001-a-16/
- Practical use of corrective actions for ISO 27001 and ISO 22301 https://advisera.com/27001academy/blog/2013/12/09/practical-use-of-corrective-actions-for-iso-27001-and-iso-22301/
See also this free online course that will teach you everything about the standard: ISO 27001 Foundations Course: https://advisera.com/training/iso-27001-foundations-course/
Comment as guest or Sign in
Jun 27, 2016