Expert Advice Community

Guest

Getting certification after risk assessment

  Quote
Guest
Guest user Created:   Jun 09, 2020 Last commented:   Jun 09, 2020

Getting certification after risk assessment

I researched about ISO 27001 and this is the latest in the market. If you can help me with providing a bit about how do we actually get the certification after the risk assessment. Like how do we approach and plan? I will be very thankful to you.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jun 09, 2020

Generally speaking, after risk assessment you need to:

  • define risk treatment
  • elaborate and approve the statement of applicability
  • develop and implement the risk treatment plan
  • operate and monitor controls (implementing corrections and improvements as necessary)
  • perform internal audit
  • perform management review
  • implement management review decisions (including the implementation of corrections and improvements as necessary)

These articles will provide you a further explanation about ISO 27001 implementation:

These materials will also help you regarding ISO 27001 implementation:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jun 09, 2020

Jun 09, 2020