Expert Advice Community

Guest

Risk Assessment

  Quote
Guest
Guest user Created:   Jun 09, 2020 Last commented:   Jun 09, 2020

Risk Assessment

Our organization is ISO27001 certified. Now we need to go for risk assessment. I am confused as our external consultant company is saying that they are using Risk Assessment Matrix as per ISO 27005 & ISO 27001.


whereas our newly hired auditor is saying that the external consulting company is wrong and we should use Nihari or Octavia..

My question is that as an ISO 27001 certified organization what should we use?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jun 09, 2020

ISO 27001 does not prescribe which methodology an organization must use for risk assessment and risk treatment, only that an approach must be defined, so organizations can adopt the approach that better fits them.

Since you are already ISO 27001 certified, the initial recommendation is for you to keep the approach adopted in the preparation for the certification (it was validated by the certification auditor), and then ask both your external consultant and the auditor about the pros and cons of each recommended approach considering your organizational context, so you can evaluate if you, in fact, need to change your current approach.

For further information, see:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jun 09, 2020

Jun 09, 2020