Asset for Risk Assessment
How do I know I have listed all assets for the risk assessment?
Assign topic to the user
The best way to check if all relevant assets are identified is by interviewing the people most related to the information the ISMS is being designed to protect (e.g., end-users, IT staff, managers, etc.). Additional information may be found in the available documentation, like procedures, and inapplicable legal requirements (e.g., laws, regulations, and contracts).
In our template for Risk assessment (https://advisera.com/27001academy/documentation/risk-assessment-table/), you will get a checklist of potential assets that could be included.
This article will provide you a further explanation about assets:
- How to handle Asset register (Asset inventory) according to ISO 27001 https://advisera.com/27001academy/knowledgebase/how-to-handle-asset-register-asset-inventory-according-to-iso-27001/
Comment as guest or Sign in
May 20, 2020