Guest
Evaluating risk assessment results
In the risk assessment conducted...i am using activity based approach. So for each activity assets would have been identified in the bia. How do i determine the result if one asset owner rates a laptop high compared to another asset owner who rates it as low?
Assign topic to the user
Expert
Rhand Leal
Feb 20, 2018
Answer: Considering they have used the same assessment criteria, then you should evaluate the impact of each activity to the business as a whole to make a decision. If both activities have similar impact, then you should rate the laptop as High, to ensure proper controls to the worst case scenario considered in your scope.
Comment as guest or Sign in
Feb 20, 2018
Feb 20, 2018
Feb 20, 2018