Expert Advice Community

Guest

Access control over Risk Assessment and Treatment Tables

  Quote
Guest
Guest user Created:   Apr 10, 2017 Last commented:   Apr 10, 2017

Access control over Risk Assessment and Treatment Tables

The RA table and Treatment should be in restricted access or anyone through the company can read it?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 10, 2017

Answer: Risk assessment and treatment tables should be accessed only by those who need to know them to plan, implement, monitor and improve controls to protect information. So, only a few people should have access to them, since most of organization's people will be users, with not active participation on controls management.

This article will provide you further explanation about access control:
- How to handle access control according to ISO 27001 https://advisera.com/27001academy/blog/2015/07/27/how-to-handle-access-control-according-to-iso-27001/

These materials will also help you regarding access control:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 10, 2017

Apr 10, 2017

Suggested Topics

Guest user Created:   Mar 31, 2019 ISO 27001 & 22301
Replies: 1
0 0

Toolkit content

Guest user Created:   Apr 23, 2018 ISO 27001 & 22301
Replies: 1
0 0

Risk assessment