Expert Advice Community

Guest

Acceptable level of risk

  Quote
Guest
Guest user Created:   Nov 29, 2016 Last commented:   Nov 29, 2016

Acceptable level of risk

Just wanted to understand. Is there an acceptable level of risk?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic Nov 29, 2016

Answer ISO 27001 does not prescribe acceptable level of risk, which means that each company must set their own acceptable level of risk - this is usually done through the Risk assessment methodology.

See these articles for explanation:
- How to write ISO 27001 risk assessment methodology https://advisera.com/27001academy/knowledgebase/write-iso-27001-risk-assessment-methodology/
- Why is residual risk so important? https://advisera.com/27001academy/knowledgebase/why-is-residual-risk-so-important/

These materials will also help you regarding acceptable level of risk:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your
Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course
https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 29, 2016

Nov 29, 2016