Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... c: EU MDR vs. MDD – What has changed? https://advisera.com/13485academy/blog/2020/11/24/infographic-eu-mdr-vs-mdd-what-has-changed/
For more information, see:
To help you in the preparation of the technical documentation, please read the following article:
... ISO 27001 vs. ISO 27017 – Information security controls for cloud services https://advisera.com/27001academy/blog/2015/11/30/iso-27001-vs-iso-27017-information-security-controls-for-cloud-services/
- ISO 27001 vs. ISO 27018 – Standard for protecting privacy in the cloud https://advisera.com/27001academy/blog/2015/11/16/iso-27001-vs-iso-27018-standard-for-protecting-privacy-in-the-cloud/
... ssessment vs. business impact analysis https://advisera.com/27001academy/knowledgebase/risk-assessment-vs-business-impact-analysis/
- How to implement business impact analysis (BIA) according to ISO 22301 https://advisera.com/27001academy/knowledgebase/how-to-implement-business-impact-analysis-bia-according-to-iso-22301/
2 - Also as per you answer, should I perform RA only for the process which I have in BIA? If that’s the case, should I consider RA w.r.t People , process and technologies boundaries? or should I consider operational and business risks as well?
Thanks
Answer: In case your purpose is to ensure business continuity, considering the ISO 22301 standard, which provides requirements for business continuity management, then you should apply RA only for the process which you have in BIA (which are all the processes included in the Business Continuity Management System scope).
Regarding risk categories, ISO 22301 does not prescribe which ones to apply, so you can define the ones that better fit your needs.
To see how documents compliant with ISO 22301 BIA and RA looks like, please take a look at the free demos of these toolkits:
- ISO 22301 Business Impact Analysis Toolkit https://advisera.com/27001academy/iso22301-business-impact-analysis-documentation-toolkit/
- ISO 27001/ISO 22301 Risk Assessment Toolkit https://advisera.com/27001academy/iso-27001-22301-risk-assessment-toolkit/
... ssessment vs. business impact analysis https://advisera.com/27001academy/knowledgebase/risk-assessment-vs-business-impact-analysis/
These materials will also help you regarding risk assessment and BIA:
... ISO 9001 toolkit, you do not maybe need to buy the whole toolkit, only some documents according to which ISO 9001 differs from ISO 13485.
Here you can find an article regarding similarities and differences between ISO 9001 and ISO1 3485:
... of Assets vs All 114 controls, it is not required. Is this correct?
Thank you very much in advance
Your assumption is right. ISO 27001 does not require a list of Assets vs. Annex A controls. As you already perceived, this approach only creates a lot of data that won’t be very useful.
The standard’s approach for the application of controls is based on the identification of applicable legal requirements and mitigation of relevant risks. This way you keep your information at a minimum, i.e., only the basic information about assets (in the inventory of assets document), the assessed risks (in the risk assessment table), and the treated risks (in the risk assessment table).
By the way, included in your toolkit you have access to a video tutorial that can help you fill in the risk assessment and risk treatment table.
This article will provide you a further explanation about risk assessment and risk treatment:
These materials will also help you regarding assets, risk assessment, and risk treatment:
... that risk assessment should cover all business processes / activities involved in the business continuity management system?
Your understanding is correct. The risk assessment must be applied to all elements defined in the BCMS scope.
These articles will provide you a further explanation about risk assessment in business continuity:
... rtunities vs. environmental aspects - https://advisera.com/14001academy/blog/2016/03/21/how-does-product-life-cycle-influence-environmental-aspects-according-to-iso-140012015/
... ce visits vs. certification audits https://advisera.com/27001academy/knowledgebase/surveillance-visits-vs-certification-audits/
- How to maintain the ISMS after the certification https://advisera.com/27001academy/blog/2014/07/14/how-to-maintain-the-isms-after-the-certification/