Expert Advice Community

Guest

Advantages/Disadvantages of Asset Based Risk Assessment

  Quote
Guest
Guest post Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Advantages/Disadvantages of Asset Based Risk Assessment

Hi All, I find that many organizations have adopted an asset based risk assessment.I am concenred that many generic risks would be missed out. I would like to know your views on pros and cons of Asset based RA. Many Thanks, Itommy
0 0

Assign topic to the user

ISO 27001 RISK ASSESSMENT AND RISK TREATMENT METHODOLOGY

Define main rules for risk assessment and treatment.

ISO 27001 RISK ASSESSMENT AND RISK TREATMENT METHODOLOGY

Define main rules for risk assessment and treatment.

Guest
DejanK Jan 12, 2016

Itommy,

It is true that many companies are still using asset-based risk assessment, although 2013 revision of ISO 27001 allows also other methods of risk identification.

If you want to avoid missing generic risks when doing the asset-based risk assessment, you should develop a list of generic threats and then make sure you check them against each asset.

Generally speaking, asset-based risk assessment is more precise than others because it focuses on each element that contains information (or could endanger the information), while on the other hand it is rather complex and lengthy. Other methodologies have still not proved themselves, so it will take couple of years more to show which will prove better in practice.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016

Suggested Topics

Lajvar Created:   Apr 29, 2024 ISO 27001 & 22301
Replies: 0
0 0

Risk treatment plan

Tanya S Created:   Dec 01, 2023 ISO 27001 & 22301
Replies: 1
0 0

Residual Risk Calculations