SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Organizational context and Risk Assessment Report

  Quote
Guest
Guest user Created:   Mar 24, 2017 Last commented:   Mar 24, 2017

Organizational context and Risk Assessment Report

1 - Do I need to prepare some reports when risk assessment and risk treatment are done? I am asking because in your template “Risk assessment and risk treatment report” there is one sentence under “Time period” there is a sentence saying:"Risk assessment was implemented in the period from xxxxxxxxxx to xxxxxxxxx. Risk treatment was implemented from xxxxxxxxx to xxxxxxx. Final reports were prepared during xxxxxxxx to xxxxxxx."
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 24, 2017

Answer: Clauses 8.2 and 8.3 from the standard require you to document the results of the risk assessment - they don't specifically require the "Report", but some kind of document that shows what risks were assessed and treated at a particular date, and excel sheets or tools used on operational activities are not very good for this purpose because they are intended to be changed any time to included changes in the risk environment.

Besides that, you also provide a document to top management where you can present the risk assessment methodology and compile, highlight and present the main risks and treatments in a forma t they are used to read (executive summary, main findings, recommendations, etc.).

In the video tutorials that came with your toolkit, you can see examples of how to fill out all the Risk assessment and Risk treatment Report.

2 - For the part “Understanding the organization” there is something called “Internal and external issues”. I think I understand but I am not sure. Can you please give me some examples of internal and external issues?

Answer: Examples of internal issues are organizational culture, assets, methodologies and policies. External issues examples are new technologies, geographical location, market conditions, and
government's laws.

This article will provide you further explanation about internal and external issues:
- Explanation of ISO 27001:2013 clause 4.1 (Understanding the organization) https://advisera.com/27001academy/knowledgebase/how-to-define-context-of-the-organization-according-to-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 24, 2017

Mar 24, 2017

Suggested Topics