SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

How to write ISO 27001 risk assessment methodology

  Quote
Guest
Guest user Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

How to write ISO 27001 risk assessment methodology

 many thanks for your mail. I tried the first document template I ordered and I like it. I will try to convince my boss to buy the rest next week. We just started our project for implementing the iso27001 in our company.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Guest
AntonioS Jan 12, 2016

maybe you can answer one question for me beforehand.... how exactly does one evaluate the impact of a risk.. you know.. the percentage stuff.. say for examble an insider incident... an insider exploits their access to steal or modify information.. how do I evaluate the raw probability and the raw impact?

 

Answer:

For me it is more easy to use scales, for example: Low, Medium or High - if you explain precisely what each of these grades mean, then it will be rather easy to assess impact or likelihood. If you want, you can see how it's done in our template “Risk Assessment and Risk Treatment Methodology”: https://advisera.com/27001academy/documentation/Risk-Assessment-and-Risk-Treatment-Methodology/

Also you can read this article where we talk about “How to write ISO 27001 risk assessment methodology”: https://advisera.com/27001academy/knowledgebase/write-iso-27001-risk-assessment-methodology/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016