Question regarding ISO Process
Assign topic to the user
Please note that in the ISO 27001 risks assessment and treatment process the risk treatment needs to be performed before developing the Statement of Applicability.
Broadly speaking, these are the steps:
- ISO 27001 risk assessment methodology
- Risk assessment implementation
- Risk treatment implementation
- Risk Assessment and Treatment Report
- Statement of Applicability
- Risk Treatment Plan
These articles will provide you a further explanation about risk assessment and risk treatment:
- 6 main steps in risk management https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/ (top of the article)
- Risk treatment https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/#treatment
Comment as guest or Sign in
Mar 03, 2022

