Expert Advice Community

Guest

Getting certification after risk assessment

  Quote
Guest
Guest user Created:   Jun 09, 2020 Last commented:   Jun 09, 2020

Getting certification after risk assessment

I researched about ISO 27001 and this is the latest in the market. If you can help me with providing a bit about how do we actually get the certification after the risk assessment. Like how do we approach and plan? I will be very thankful to you.

0 0

Assign topic to the user

ISO 27001 RISK ASSESSMENT AND TREATMENT REPORT

Document the results of the risk management process.

ISO 27001 RISK ASSESSMENT AND TREATMENT REPORT

Document the results of the risk management process.

Expert
Rhand Leal Jun 09, 2020

Generally speaking, after risk assessment you need to:

  • define risk treatment
  • elaborate and approve the statement of applicability
  • develop and implement the risk treatment plan
  • operate and monitor controls (implementing corrections and improvements as necessary)
  • perform internal audit
  • perform management review
  • implement management review decisions (including the implementation of corrections and improvements as necessary)

These articles will provide you a further explanation about ISO 27001 implementation:

These materials will also help you regarding ISO 27001 implementation:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jun 09, 2020

Jun 09, 2020