SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Risk Acceptance Criteria and Residual Risk

  Quote
Guest
Guest post Created:   Jan 12, 2016 Last commented:   Jan 12, 2016

Risk Acceptance Criteria and Residual Risk

Hi friends, I have a question if you can help me. I'm establishing the Risk Methodology and I have established the risk levels and the Risk Acceptance Criteria, my question is: the residual risk is explicity in the risk acceptance criteria?? Or how I can establish the Residual Risk in my methodology? and its treatment?? Thank you so much Best Regards
0 0

Assign topic to the user

ISO 27001 RISK TREATMENT PLAN

Determine responsibilities for the implementation of controls.

ISO 27001 RISK TREATMENT PLAN

Determine responsibilities for the implementation of controls.

Guest
DejanK Jan 12, 2016

Cesar,

Residual risk is the risk that has remained after the treatment of risks - for example, if you had a risk that had a level of 9, and by treating it you have reduced it to 6, this level of 6 is the residual risk.

After you calculate this residual risk, you have to see whether it is acceptable - for example, if your acceptable level of risk is 7, this would mean that this residual risk of 6 is acceptable; if your acceptable level of risk is 5, in such case you would need to reduce this risk further, or ask the risk owners to explicitly accept such risk without reducing it further.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 12, 2016

Jan 12, 2016