SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

ISO 31000 and ISO 27005

  Quote
Guest
Guest user Created:   Apr 14, 2016 Last commented:   Apr 14, 2016

ISO 31000 and ISO 27005

If any organisation is comply with ISO 31000 so it can comply with ISO 27005 or no?
0 0

Assign topic to the user

ISO 27001 RISK ASSESSMENT AND RISK TREATMENT METHODOLOGY

Define main rules for risk assessment and treatment.

ISO 27001 RISK ASSESSMENT AND RISK TREATMENT METHODOLOGY

Define main rules for risk assessment and treatment.

Guest
Antonio Jose Segovia Apr 14, 2016

Answer:
From my point of view no, because ISO 27005 is specially developed to provide guidelines on how to organize information security risk management, and ISO 31000 is developed to provide guidelines on how to organize global risk management, so if you have an ISMS (Information Security Management System) and you have information security risks, the best way (and the logic way) is to use ISO 27005. Anyway, remember that both standards are only code of best practices, you cannot certify them. For more information, please read this article “ISO 31000 and ISO 27001 – How are they related?” : https://advisera.com/27001academy/blog/2014/03/31/iso-31000-and-iso-27001-how-are-they-related/

And if you are interested in ISO 27001, our online course can be also interesting for you “ISO 27001:2013 Foundations Course” : https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 14, 2016

Apr 14, 2016