Expert Advice Community

Guest

8.3 Tratamiento de los riesgos de seguridad de información

  Quote
Guest
juancarlos8888 Created:   Aug 28, 2018 Last commented:   Aug 30, 2018

8.3 Tratamiento de los riesgos de seguridad de información

Hola, En este punto de la norma hay algún formato que se deba seguir para documentar la implementanción del plan de tratamiento de riesgos? Si en el plan de tratamiento de riesgos hay un proyecto identificado para mitigar una serie de riesgos,¿el comité de seguridad podría a posteriori decidir que se acepta el riesgo y no se implementa ese proyecto? o eso seria una no conformidad ya que el riesgo aceptado o "apetito de riesgo " nos obliga a tratar ese riesgo con el proyecto identificado en el plan de tratamiento.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Aug 30, 2018

>1 - At this point in the standard, is there any format that should be followed to document the implementation of the risk treatment plan?

Answer: ISO 27001 does not prescribe any format for the risk treatment plan, so you can develop the document in the format that best fits your organization's needs. To see how a risk treatment plan looks like I suggest you to take a look a the free demo of our Risk Treatment Table template at this link: https://advisera.com/27001academy/documentation/risk-treatment-plan/

This material will provide you more information:
- The basics of risk assessment and treatment according to ISO 27001 [free webinar on demand] https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/

>2 - If there is a project identified in the risk treatment plan to mitigate a series of risks, could the security committee later decide that the risk is accepted and that project is not implemented? or that would be a non-conformity since the accepted risk or "risk appetite" obliges us to treat this risk wit h the project identified in the treatment plan.

Answer: You can change the status of any action in the risk treatment plan at any time. You only have to take care to keep evidences of the decisions made to change the risk treatment plan and to record the newly accepted risks in the risk assessment table.

Quote
0 0
Guest
juancarlos8888 Aug 30, 2018

Thanks a lot Rhand Leal!

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Aug 28, 2018

Aug 30, 2018

Suggested Topics