How do I handle the risk of control?
1. How does one put in the risk/control of the asset?
I have read your website in terms of implementation isms for iso27001.
First I have classified my assets, label them, checked the risk of each.
Now how will this relate to the iso controls?
That I don't understand is that the iso has annex, controls and some questions (or advice)
Because... let me take an example of an annex
Ok, let's say employees are also an asset. So taking the annex 7.2.2
"Information security awareness, education and training"
Objective
All employees of the organization and, where relevant, contractors shall receive appropriate awareness education and training and regular updates in organizational policies and procedures, as relevant for their job function.
Does this mean one just has to educate the workers and partners on policies and then he is compliant to this annex?
2. I watched one of your videos about ISO27001, whereby the speaker gave a simple method of risk assessment table. So what impact is that table having on the iso requirement?
3. Assuming I have 10 assets but 3 are having a risk but 7 are okay.... which controls of the ISO27001 is this related to?
Assign topic to the user
1. How does one put in the risk/control of the asset?
I have read your website in terms of implementation isms for iso27001.
First I have classified my assets, label them, checked the risk of each.
Now how will this relate to the iso controls?
That I don't understand is that the iso has annex, controls and some questions (or advice)
Because... let me take an example of an annex
Ok, let's say employees are also an asset. So taking the annex 7.2.2
"Information security awareness, education and training"Objective
All employees of the organization and, where relevant, contractors shall receive appropriate awareness education and training and regular updates in organizational policies and procedures, as relevant for their job function.
Does this mean one just has to educate the workers and partners on policies and then he is compliant to this annex?
I'm understanding that you want to clarify how controls from ISO 27001 Annex A are linked to identified risks.
Considering that, you need to identify which control's requirements best treat the risk you want to mitigate.
In your example, you only identified the asset (employees), but let's say one identified risk is that "New employee shared his/her password because he was unaware of corporate policies". From this risk statement, you can see that the control 7.2.2 can be used to treat this risk.
For further information see:
- ISO 27001 risk assessment: How to match assets, threats and vulnerabilities https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-how-to-match-assets-threats-and-vulnerabilities/
- How to assess consequences and likelihood in ISO 27001 risk analysis https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/#assessment
- A quick guide to ISO 27001 controls from Annex A https://advisera.com/27001academy/iso-27001-controls/
This material can also help you understand how to link risks to controls:
- Diagram of ISO 27001:2013 Risk Assessment and Treatment process (PDF) https://info.advisera.com/27001academy/free-download/diagram-of-iso-270012013-risk-assessment-and-treatment-process
2. I watched one of your videos about ISO27001, whereby the speaker gave a simple method of risk assessment table. So what impact is that table having on the iso requirement?
ISO 27001 requires a definition of a risk assessment approach to identify and analyze risks (clause 6.1.3), so this table will help fulfill this requirement (without a defined approach an organization cannot be certified against ISO 27001).
3. Assuming I have 10 assets but 3 are having a risk but 7 are okay.... which controls of the ISO27001 is this related to?
I'm sorry, but without information about the risks, it is not possible to provide information about which controls can be applied.
Comment as guest or Sign in
Jul 07, 2020