SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Handling assets

  Quote
Guest
Guest user Created:   Dec 11, 2019 Last commented:   Dec 11, 2019

Handling assets

When identifying assets, can I lump them together or is it each one individually that needs a Risk Assessment completed?

Eg. 10 Servers are identified as critical assets. Can I do a Risk Assessment on Servers or do I need to list CLIENTSVR01 in the risk register.

0 0

Assign topic to the user

ISO 27001 RISK TREATMENT PLAN

Determine responsibilities for the implementation of controls.

ISO 27001 RISK TREATMENT PLAN

Determine responsibilities for the implementation of controls.

Expert
Rhand Leal Dec 11, 2019

In case an inventory of assets is applicable to your organization, ISO 27001 does not prescribe how it must handle assets, so you can group them as best they fit your organization's needs.

For example, you can group your servers if they have similar characteristics, or share similar risks.

This article will provide you further explanation about asset register:
- How to handle Asset register (Asset inventory) according to ISO 27001 https://advisera.com/27001academy/knowledgebase/how-to-handle-asset-register-asset-inventory-according-to-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 11, 2019

Dec 11, 2019