1 - I am filling out the Risk Assessment and Treatment Methodology document in the documentation toolkit. I have already listed out all the assets and their threats, vulnerabilities, and owners. My question is on filling out the risk criteria, specifically the likelihood. Do I take the existing controls into consideration for determining total risk?
Continuing Professional Education (CPE) and ISO 270001
how many CPE's come with completing the ISO 270001 continuing professional education?
1) From where to get PCI DSS documents and standard ?
Implementing ISO 27001 polices
if you appoints a chairman of your district how do you empliment policy?
SOP for threats and vulnerability assessment
Could you kindly guide from where can I get the SOP (Standard operating procedure) for Threats and Vulnerability Assessment.
Why are some documents mandatory?
Why is 8.1.1 mandantory and 8.2.1 not mandantory? the norm gives me no hints. can you tell me the text parts of the ISO where I can rean the mandantory needs?
Cost of the certification audit; managing ISO documents
1.What is the cost of certification audit?
Identification of risks caused by third parties
Which are the most common risks in outsourced data center?