Expert Advice Community

Guest

Asset inventory question

  Quote
Guest
Guest user Created:   Nov 10, 2016 Last commented:   Nov 10, 2016

Asset inventory question

My question is how detailed this asset inventory should be. For example, the employees laptops are in the scope, do I have to list in this sheet the laptop of each employee or is it enough to have a generic term "employees laptops" and list the vulnerabilities threats in this way. If I use a term like "employees laptops" do I need to make a reference to a more comprehensive list that lists down all the laptops one by one?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic Nov 10, 2016

Answer: For risk assessment it is enough to have a generic asset class "employee laptops", and list threats and vulnerabilities for this single asset. If you already have a comprehensive list of laptops, this is something you can do, but this is not mandatory according to ISO 27001.

Now regarding processes, do I have to include a process like "transferring data from Server A to Server B" - Such a process is very important for the organisation.

Answer: If you use asset-based risk assessment, then listing processes is not needed - basically all this data that you are transferring is already covered in the r isk assessment as assets, so you don't need to duplicate them. The focus of information security is protecting the information, not protecting the processes.

These materials will also help you with risk assessment:
- article ISO 27001 risk assessment: How to match assets, threats and vulnerabilities https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-how-to-match-assets-threats-and-vulnerabilities/
- free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/
- book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Nov 10, 2016

Nov 10, 2016

Suggested Topics