Expert Advice Community

Guest

Risk Assessment Methodology.

  Quote
Guest
sujansuresh Created:   Aug 05, 2016 Last commented:   Aug 06, 2016

Risk Assessment Methodology.

What is the basic risk assessment methodology used in ISO 27001? What is FEMA and FISMA? What are all the cases in which a special methodology of risk assessment is chosen? What are all the other methodologies which are being used? Kindly help, TIA.
0 0

Assign topic to the user

ISO 27001 RISK ASSESSMENT AND RISK TREATMENT METHODOLOGY

Define main rules for risk assessment and treatment.

ISO 27001 RISK ASSESSMENT AND RISK TREATMENT METHODOLOGY

Define main rules for risk assessment and treatment.

Guest
Antonio Jose Segovia Aug 06, 2016

There is no specific methodology in ISO 27001 for the risk assessment (you can develop your own methodology), although this article can help you to write a basic risk assessment methodology “How to write ISO 27001 risk assessment methodology” : https://advisera.com/27001academy/knowledgebase/write-iso-27001-risk-assessment-methodology/

FEMA (Federal Emergency Management Agency) and FISMA (Federal Information Security Management Act) are basically regulations that are applicable only in USA.

Most of cases the risk assessment methodology chosen is an asset based, because it is the most easy, and common methodologies are CRAMM, OCTAVE, MAGERIT, but as you know, you can write your own methodology.

This article can be also interesting for you “ISO 31010: What to use instead of the asset-based approach for ISO 27001 risk identification” : https://advisera.com/27001academy/blog/2016/04/04/iso-31010-what-to-use-instead-of-the-asset-based-approach-for-iso-27001-risk-identification/

Finally, these materials will help you more with risk assessment:
- free online training ISO 2700 1 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
- book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Aug 05, 2016

Aug 06, 2016

Suggested Topics