ISMS risk calculation
I would like to know what standard is the risk calculation for ISMS, please?
I want to know what standard iso-27001 use for risk determination, or risk calculation.
Actually what documents explain step by step to risk calculation in an enterprise
Assign topic to the user
The main standard for information security risk management is the ISO 27005, which you can see a preview at this link: https://www.iso.org/standard/75281.html
These articles will provide you further explanation about risk identification and calculation:
- ISO 27001 risk assessment & treatment – 6 basic steps https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/
- ISO 27001 risk assessment: How to match assets, threats, and vulnerabilities https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-how-to-match-assets-threats-and-vulnerabilities/
- How to assess consequences and likelihood in ISO 27001 risk analysis https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/#assessment
These materials will also help you regarding risk identification and calculation:
- The basics of risk assessment and treatment according to ISO 27001 [free webinar] https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/
- Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
Comment as guest or Sign in
Nov 29, 2019