Expert Advice Community

Guest

Risk assessment process

  Quote
Guest
Guest user Created:   Feb 13, 2020 Last commented:   Feb 13, 2020

Risk assessment process

I wanted to find out which ISO 27001 output documents are to be made ready before the Risk Assessment process commences?

0 0

Assign topic to the user

ISO 27001 RISK ASSESSMENT TABLE

Implement risk register using catalogues of vulnerabilities and threats.

ISO 27001 RISK ASSESSMENT TABLE

Implement risk register using catalogues of vulnerabilities and threats.

Expert
Rhand Leal Feb 13, 2020

Considering the most common steps for implementation of ISO 27001, the following mandatory documents must be available before risk assessment starts:

  • Scope of the ISMS (clause 4.3)
  • Information security policy and objectives (clauses 5.2 and 6.2)

The risk assessment and risk treatment methodology is not a mandatory document (the standard only requires the process to be defined and implemented), but it is considered a good practice to have the methodology documented.

The Scope will define which assets and/or processes are included in the ISMS, which is the base for doing the risk assessment. The Information security policy will define basic responsibilities. 

This article will provide you a further explanation about implementation steps:

These materials will also help you regarding implementation steps:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 13, 2020

Feb 13, 2020

Suggested Topics