SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Risk Analysis

  Quote
Guest
Guest user Created:   Mar 25, 2020 Last commented:   Mar 25, 2020

Risk Analysis

Estoy creando documentación para gestión de Riesgo, La documentación dice evaluación de riesgo, quiero saber cual es el GAP que me faltaría o estamos hablando de lo mismo. El requisito a cumplir es: Implementar un proceso formal de gestión de riesgos de información que incluya la identificación y clasificación de los activos de información, impacto de riesgo, probabilidad de riesgo y puntajes de riesgo con definiciones cuantitativas, tratamientos de riesgo, definición de planes de tratamiento, seguimientos formales, implementación de reuniones del comité directivo y re-visita cicle de acuerdo con ISO-27005 y ejecute la primera evaluación anual de riesgos.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 25, 2020

I am creating documentation for Risk Management, The documentation says risk assessment, I want to know which GAP is missing or we are talking about the same. The requirement to be met is: Implement a formal information risk management process that includes the identification and classification of information assets, risk impact, risk probability and risk scores with quantitative definitions, risk treatments, definition of plans treatment, formal follow-ups, implementation of steering committee meetings and cycle re-visit in accordance with ISO-27005 and execute the first annual risk assessment

 I'm assuming you are referring to the ISO 27001/ISO 22301 Risk Assessment Toolkit when you say "La documentación dice evaluación de riesgo" (The documentation says risk assessment).

Considering that, the toolkit covers all requirements for risk assessment and treatment defined by ISO 27001, which also recommends the adoption of ISO 27005 (there are no GAPs in the documentation). In the toolkit, you will find the following documents:

  • Risk Assessment and Risk Treatment Methodology
  • Risk Assessment Table
  • Risk Treatment Table
  • Risk Assessment and Treatment Report
  • Statement of Applicability
  • Risk Treatment Plan

To see how the documents look like, please access the free demo at this link: https://advisera.com/27001academy/iso-27001-22301-risk-assessment-toolkit/

This article will provide you further explanation about risk management for ISO 27001:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 25, 2020

Mar 25, 2020

Suggested Topics

Guest user Created:   Dec 05, 2020 ISO 27001 & 22301
Replies: 1
0 0

Risk analysis