Expert Advice Community

Guest

IT Risk Management Material

  Quote
Guest
Guest user Created:   Aug 23, 2017 Last commented:   Aug 23, 2017

IT Risk Management Material

I am talking to a client in the telecom space. They have asked me to help with the best practices for IT Risk Management as they are in the process of implementing IT GRC. I would appreciate if you could share some material on the same. What comes to my mind is ISO 27005, NIST and Risk IT. I would take any material that you could share.
0 0

Assign topic to the user

ISO 27001 RISK ASSESSMENT AND TREATMENT REPORT

Document the results of the risk management process.

ISO 27001 RISK ASSESSMENT AND TREATMENT REPORT

Document the results of the risk management process.

Expert
Rhand Leal Aug 23, 2017

Answer: IT Risk Management goes well beyond information security risks, so besides the material you already mentioned, I'd recommend you to take a look at our 20000Academy, which focus on ISO 20000 and ITIL content. Some material you will find there, are:
- ITIL Risk response measures and recovery options from catastrophic events https://advisera.com/20000academy/blog/2015/09/22/itil-risk-response-measures-and-recovery-options-from-catastrophic-events/
- Risk Assessment and Treatment (template) https://advisera.com/20000academy/documentation/risk-assessment-and-treatment/
- IT Service Continuity Management (ITSCM) Process https://advisera.com/20000academy/documentation/it-service-continuity-management-process-iso-20000/ process/

Regarding ISO standards, I'd recommend ISO 31000 (Risk management) and ISO 31010 ( Risk management — Risk assessment techniques). These will provide you a wider view of risk management that can help you with IT risks not necessarily related to information security.

These articles will provide you further explanation about ISO 31000 and ISO 31010:
- ISO 31000 and ISO 27001 – How are they related? https://advisera.com/27001academy/blog/2014/03/31/iso-31000-and-iso-27001-how-are-they-related/
- ISO 31010: What to use instead of the asset-based approach for ISO 27001 risk identification https://advisera.com/27001academy/blog/2016/04/04/iso-31010-what-to-use-instead-of-the-asset-based-approach-for-iso-27001-risk-identification/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Aug 23, 2017

Aug 23, 2017

Suggested Topics