Expert Advice Community

Guest

Listing mitigated risks in RAT

  Quote
Guest
Guest user Created:   May 07, 2021 Last commented:   May 07, 2021

Listing mitigated risks in RAT

1 – In the RAT, presumably I do not list risks that are already mitigated?

2 – Is it possible to see an example of a real and completed RAT, preferably for a SaaS business?

0 1

Assign topic to the user

Assign

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal May 07, 2021

1 – In the RAT, presumably I do not list risks that are already mitigated?

When performing Risk Assessment and Treatment you need to include every risk you understand as relevant, even if there are controls already implemented to treat them.

If you already have controls implemented, you should consider their effects on the risk value, so that your risk assessment table reflects the current situation of your environment. The existing controls should be included in the "Existing Controls" column in your Risk Assessment Table template.

By the way, included in the toolkit you bought you have access to a video tutorial that can help you fill the risk assessment and risk treatment tables.

These articles will provide you a further explanation about risk assessment:

These materials will also help you regarding risk assessment:

2 – Is it possible to see an example of a real and completed RAT, preferably for a SaaS business?

Unfortunately, we do not have example documents we can disclose due to confidentiality agreements with our customers.

By the way, included in the toolkit you bought, you have access to video tutorials that can help you fill in the risk assessment and risk treatment templates.

For examples of risk assessment, I can suggest you these materials:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

May 07, 2021

May 07, 2021