Start a new topic and get direct answers from the Expert Advice Community.
CREATE NEW TOPIC +Guest
... sk owners vs. asset owners in ISO 27001:2013 https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/
- ISO 27001 risk assessment: How to match assets, threats and vulnerabilities https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-how-to-match-assets-threats-and-vulnerabilities/
2. Assessing consequence and likelihood of risk is responsible by risk owner?
Answer:
Risk owner is a person designated to solve a risk, and to do so he must be responsible for performing consequence and likelihood assessment, either by himself or with support of other personnel.
This article will provide you further explanation about assessing likelihood and consequence:
- How to assess consequences and likelihood in ISO 27001 risk analysis https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/#assessment
3. So for the one who is responsible for Risk assessment just pick up from them and then do the risk assessment?
Answer:
Risk assessment is the combination of risk identification, risk analysis and risk evaluation, so it is not a simple question of picking up risks, but identify them, define values for them, so they can be prioritized, and evaluate them against your criteria, so you can decide which ones have to be treated.
These materials will also help you regarding risk assessment:
- The basics of risk assessment and treatment according to ISO 27001 [free webinar] https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/
- Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
... analysis vs. risk assessment https://advisera.com/27001academy/knowledgebase/iso-27001-gap-analysis-vs-risk-assessment/
- ISO 27001 implementation checklist https://advisera.com/27001academy/knowledgebase/iso-27001-implementation-checklist/
These materials will also help you regarding ISO 27001 implementation:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
... ISO 27001 vs. ITIL: Similarities and differences https://advisera.com/27001academy/blog/2016/03/07/iso-27001-vs-itil-similarities-and-differences/
- Using ITIL to implement ISO 27001 incident management https://advisera.com/27001academy/blog/2015/11/10/using-itil-to-implement-iso-27001-incident-management/ t/
- How to implement ISO 27001 and ISO 20000 together https://advisera.com/27001academy/blog/2015/03/16/how-to-implement-iso-27001-and-iso-20000-together/
- How to integrate ISO 27001 and ISO 20000 [free webinar on demand] https://advisera.com/27001academy/webinar/how-to-integrate-iso-27001-and-iso-20000-free-webinar-on-demand/
... ification-vs-course-certifications-what-are-the-differences-free-webinar-on-demand/" class="content-link Link" target="_blank" >https://advisera.com/9001academy/webinar/personnel-certification-vs-course-certifications-what-are-the-differences-free-webinar-on-demand/
On our Advisera eTraining website you c an gain personal certification for ISO 9001 that is basic for IATF 16949:
https://advisera.com/training/
... alitative vs. quantitative risk assessments in information security: Differences and similarities https://advisera.com/27001academy/blog/2017/03/06/qualitative-vs-quantitative-risk-assessments-in-information-security/
This material will also help you regarding risk assessment:
- Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
... reviously unidentified problem in the calculation system you may need to take action to put in place the temporary check procedures and systems corrections and updates necessary to address this risk which could entail a very lengthy implementation plan.
For a better understanding of how the corrective action proce ss differs from improvement see this article, âÂÂCorrective actions vs. continual improvement in AS9100âÂÂ, https://advisera.com/9100academy/knowledgebase/corrective-actions-vs-continual-improvement-in-as9100/