Expert Advice Community

Guest

Risk Assessment and frequency

  Quote
Guest
Guest user Created:   Jan 13, 2016 Last commented:   Jan 13, 2016

Risk Assessment and frequency

0 0

Assign topic to the user

ISO 27001 RISK ASSESSMENT AND RISK TREATMENT METHODOLOGY

Define main rules for risk assessment and treatment.

ISO 27001 RISK ASSESSMENT AND RISK TREATMENT METHODOLOGY

Define main rules for risk assessment and treatment.

Guest
AntonioS Jan 13, 2016

I want to know how often Risk Assessment needs to be performed as per iso 27001
 

Answer:

In accordance with the clause 8.2 Information security risk assessment of ISO 27001:2013: “The organization shall perform information security risk assessments at planned intervals or when significant changes are proposed or occur….”.
So, you can establish the frequency, although generally can be recommendable once a year.
Finally, do you know the 6 basic steps of the risk assessment & treatment? Please read this article “ISO 27001 risk assessment & treatment – 6 basic steps” : https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 13, 2016

Jan 13, 2016

Suggested Topics

Guest user Created:   Oct 06, 2020 ISO 27001 & 22301
Replies: 2
0 1

Questions about risk

Guest user Created:   Mar 06, 2020 ISO 27001 & 22301
Replies: 1
0 0

Toolkit content

Guest user Created:   Feb 07, 2023 ISO 27001 & 22301
Replies: 1
0 0

Conformio documentation