SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Performing risk assessment

  Quote
Guest
Guest user Created:   Dec 27, 2017 Last commented:   Jan 06, 2018

Performing risk assessment

I have a problem in understanding the risk assessment. Suppose that i am an ISMS consultant in an organization. I must do "risk assessment". Here is the problem. should i first define some policies for the organization and then do the risk assessment? or first i should do the risk assessment and based on it, define some policies? If the latter is correct, how can i do it? For example for assessing the risks about the password, if the organization doesn't have any password policy, how can i determine that the risk assessment should be based on 8-character passwords or 10-character passwords?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Dec 27, 2017

Answer: The better approach is to perform the risk assessment before defining policies. This way you can ensure the policies will cover the relevant results of the risk assessment and avoid rework.

If the organization does not have implemented policies by the time you have to perform the risk assessment, you can rely on other sources of requirements such as laws or contracts the organization must comply with, incidents history, and common practices adop ted by the industry.

These articles will provide you further explanation about risk assessment:
- ISO 27001 risk assessment & treatment – 6 basic steps ISO 27001 risk assessment & treatment – 6 basic steps
- ISO 27001 risk assessment: How to match assets, threats and vulnerabilities https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-how-to-match-assets-threats-and-vulnerabilities/

These materials will also help you regarding risk assessment:
- Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
- The basics of risk assessment and treatment according to ISO 27001 [free webinar on demand] https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/

Quote
0 0
Guest
saeed_orage Jan 06, 2018

So, this will help us to know the culture of the organization in following the regulations, policies and etc. And it's helpful in preparing the organization context document, because there is a PESTLE analysis in this document and "S" stand for sociocultural factors. What is your idea? Is my conclusion correct?

Quote
0 0
Expert
Rhand Leal Jan 11, 2018

Your conclusion is correct. By understanding which policies are already implemented and which risks are identified and considered relevant you can have a snapshot of the organization's culture, as well as some perception of the cultures of the other organizations which have business with it.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 26, 2017

Jan 11, 2018

Suggested Topics