SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

People "asset" for risk assessment

  Quote
Guest
Guest user Created:   Mar 18, 2016 Last commented:   Mar 18, 2016

People "asset" for risk assessment

How we can identify confidentiality, integrity and availability requirements of “people” assets for risk assessment. I will appreciate if you can provide some details.
0 0

Assign topic to the user

ISO 27001 RISK ASSESSMENT AND TREATMENT REPORT

Document the results of the risk management process.

ISO 27001 RISK ASSESSMENT AND TREATMENT REPORT

Document the results of the risk management process.

Guest
Antonio Jose Segovia Mar 18, 2016

Answer:
I am sorry but in the ISO 27001:2013 it is not necessary to identify confidentiality, integrity and availability requirements of “people” assets for risk assessment, because the term “assets” is not used in the new ISO 27001:2013 (you can develop your own methodology for the risk management, I mean, it is not mandatory to have a methodology based on assets).

Anyway, if you have a methodology asset based, you need to identify threats/vulnerabilities related to each asset, so in the case of assets of type people, a threat can be unavailability of a person, and a vulnerability can be no replacement for the position of this person (which can be considered a potential loss of availability), other threat can be frequent errors, and a vulnerability can be lack of training (which can be considered a potential loss of integrity and availability), and other threat can be illegal processing of data, and a vulnerability can be lack of monitoring mechanisms (which can be considered a potential loss of confidentiality).

For more information about this, please read this article “ISO 27001 risk assessment: How to match assets, threats and vulnerabilities” : https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-how-to-match-assets-threats-and-vulnerabilities/

And our online course can be also interesting for you because we also give information about the risk assessment, including the asset inventory “ISO 27001:2013 Foundations Course” : https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 18, 2016

Mar 18, 2016