SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Question regarding ISO Process

  Quote
Guest
Guest user Created:   Mar 03, 2022 Last commented:   Mar 03, 2022

Question regarding ISO Process

Is the best step forward to now trying to map the risks against the SOA and hand out responsibilities for controls? Or should we instead focus on the risk treatment for our "red" risks?
0 0

Assign topic to the user

ISO 27001 RISK TREATMENT PLAN

Determine responsibilities for the implementation of controls.

ISO 27001 RISK TREATMENT PLAN

Determine responsibilities for the implementation of controls.

Expert
Rhand Leal Mar 03, 2022

Please note that in the ISO 27001 risks assessment and treatment process the risk treatment needs to be performed before developing the Statement of Applicability.

Broadly speaking, these are the steps:

  • ISO 27001 risk assessment methodology
  • Risk assessment implementation
  • Risk treatment implementation
  • Risk Assessment and Treatment Report
  • Statement of Applicability
  • Risk Treatment Plan

These articles will provide you a further explanation about risk assessment and risk treatment:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 03, 2022

Mar 03, 2022

Suggested Topics

Guest user Created:   Oct 04, 2023 ISO 27001 & 22301
Replies: 1
0 0

Conformio questions