Expert Advice Community

Guest

Information Security Risk Metrics

  Quote
Guest
Guest user Created:   Sep 05, 2017 Last commented:   Sep 05, 2017

Information Security Risk Metrics

What will be the Information Security Risk Metrics or KRI (key risk indicators )?
0 0

Assign topic to the user

ISO 27001 RISK ASSESSMENT AND RISK TREATMENT METHODOLOGY

Define main rules for risk assessment and treatment.

ISO 27001 RISK ASSESSMENT AND RISK TREATMENT METHODOLOGY

Define main rules for risk assessment and treatment.

Expert
Rhand Leal Sep 05, 2017

Answer: There is no specific answer for this question, because each organization has an unique context (e.g., competitors, customers, legal requirements, risk appetite, etc.) that will define its security objectives, and after them, which risks should be monitored through indicators. For example, for an Internet-based business, a security objective may be system's uptime, and a risk indicator could be the number of discovered zero-day vulnerabilities that can result in infrastructure downtime.

These articles will provide you further explanation about control objectives and key indicators:
- ISO 27001 control objectives – Why are they important? https://advisera.com/27001academy/blog/2012/04/10/iso-27001-control-objectives-why-are-they-important/
- Key performance indicators for an ISO 27001 ISMS https://advisera.com/27001academy/blog/2016/02/01/key-performance-indicators-for-an-iso-27001-isms/

These materials will also help you regarding control objectives an d key indicators:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Sep 05, 2017

Sep 05, 2017

Suggested Topics

Guest user Created:   Feb 07, 2023 ISO 27001 & 22301
Replies: 1
0 0

Conformio documentation

Guest user Created:   Nov 27, 2018 ISO 27001 & 22301
Replies: 1
0 0

Scope extension