ISO 27001 / Conformio questions
Assign topic to the user
1. How should we treat the risk assessment process? Should we consider all the risks within our company and go over a bit or should we be more conservative? For example, should we consider our CEO being on leave as a risk while doing the risk assessment?
Considering the Conformio platform, first, you need to define your Risk Assessment and Risk Treatment Methodology. In the document provided by Conformio, you will define the risk acceptance criteria, i.e., when identified and analyzed risks must be treated. Conformio automatically determines which risks need to be treated based on the acceptance criteria you define.
For further information, see:
- How to use Conformio ISO 27001 risk assessment software https://advisera.com/conformio/blog/2021/06/27/how-to-use-conformio-iso-27001-risk-assessment-software/
2. In terms of SoA should we mark all the controls as applicable? How should we approach this?
Considering the Conformio platform, Conformio automatically marks controls applicable based on the results of risk assessment and legal requirements.
For further information, see:
- How to automate the creation of the Statement of Applicability https://advisera.com/conformio/blog/2021/01/20/how-to-automate-the-creation-of-statement-of-applicability/
Comment as guest or Sign in
Feb 08, 2022