Expert Advice Community

Guest

Existing controls decrease the level of risk

  Quote
Guest
Guest user Created:   Jul 11, 2016 Last commented:   Jul 12, 2016

Existing controls decrease the level of risk

I did the risk assessment and go the risk level for every asset. Then the current controls maturity were evaluated accordingly to the CMM levels. The risk scale is from 0 to 4 and the acceptance level is below 2. The controls recude the current risk to below 2 level, so there is not need for a risk treatment plan. This is correct? or I'm missing something?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic Jul 11, 2016

Answer:

Your process is correct - if you have controls currently in place, they will reduce the risk to an acceptable level, so no new controls will be needed. However, in most cases during the risk assessment you'll find the risks for which you do not have controls for, so for such risks you will have to identify controls in the risk treatment - for example, very often there are no controls in place against risks related to your own employees (e.g. system administrator with malicious intent) or for external services (e.g. cloud service provider cancelling your account).

I assume you already watched the risk assessment video tutorial that comes with the toolkit, and these articles w ill also help you:
- How to assess consequences and likelihood in ISO 27001 risk analysis https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/#assessment
- 4 mitigation options in risk treatment according to ISO 27001 https://advisera.com/27001academy/blog/2016/05/16/4-mitigation-options-risk-treatment-according-iso-27001/

By the way, risk assessment process is also explained in this free online training: ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0
Guest
gus85 Jul 12, 2016

Nice topic!! always helpful. Thanks a lot!

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 11, 2016

Jul 12, 2016