Expert Advice Community

Guest

Consequence and Likelihood after Risk Treatment

  Quote
Guest
Guest user Created:   Feb 11, 2020 Last commented:   Feb 11, 2020

Consequence and Likelihood after Risk Treatment

We are developing our Risk Register using the Advisera Templates. We have to mention the values of Consequence and Likelihood after the Risk Treatment i.e. Residual Risk. Will application of a control reduce the “Consequence” as well.

For example “Unauthorized Physical Access to data Center” may have a “High” consequence and “Medium” likelihood. After application of controls like CCTV/Door Lock we can reduce likelihood to “low” but will it reduce the “Consequence” as well.

Even after the control is applied if there is a breach it will have the same Consequences.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Feb 11, 2020

Not all controls affect the consequence and likelihood at the same time. The controls you mentioned works only to prevent Unauthorized Physical Access. Once access is gained, they cannot provide any means to avoid damage to assets. Examples of controls you can consider to reduce the impact on information assets are backup and redundancy.

This article will provide you a further explanation about controls selection:

These materials will also help you regarding controls selection:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 11, 2020

Feb 11, 2020

Suggested Topics

Guest user Created:   Jun 15, 2020 ISO 27001 & 22301
Replies: 1
0 0

Risk Treatment

Guest user Created:   Jun 05, 2020 ISO 27001 & 22301
Replies: 3
0 0

Inventory of Assets template