Risk assessment
Assign topic to the user
Answer: For creation of a risk assessment you should consider:
- Definition of how to identify the risks to information security
- Definition of how to identify risk owners
- Definition of criteria for assessing consequences and likelihood of the risk
- Definition of how calculate the risk
- Definition of criteria for accepting risks
Regarding the risk analysis, the main approaches are qualitative and quantitative analysis
These articles will provide you further explanation about Risk assessment:
- How to write ISO 27001 risk assessment methodology https://advisera.com/27001academy/knowledgebase/write-iso-27001-risk-assessment-methodology/
- ISO 27001 risk assessment & treatment – 6 basic steps https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/
- Qualitative vs. quantitative risk assessments in information security: Differences and simila rities https://advisera.com/27001academy/blog/2017/03/06/qualitative-vs-quantitative-risk-assessments-in-information-security/
These materials will also help you regarding Risk assessment:
- Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
- The basics of risk assessment and treatment according to ISO 27001 [free webinar] https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/
For environmental impact assessment, I suggest you to take a look at these articles:
- ISO 14001:2015 – How to set criteria for environmental aspects evaluation https://advisera.com/14001academy/blog/2016/10/31/iso-140012015-how-to-set-criteria-for-environmental-aspects-evaluation/
- ISO 14001 risks and opportunities vs. environmental aspects https://advisera.com/14001academy/blog/2016/06/06/iso-14001-risks-and-opportunities-vs-environmental-aspects/
Comment as guest or Sign in
Jun 06, 2017