SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Risk assessment and SOA

  Quote
Guest
Guest user Created:   Mar 21, 2018 Last commented:   Mar 21, 2018

Risk assessment and SOA

Our team is currently working through the risk assessment and risk treatment for items identified as being in scope of our ISMS. Our initial ISMS is being restricted to our “customer facing applications” and hence the number of category 3 and 4 risks identified is quite low. Perhaps we are being not thorough enough, which may be possible.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 21, 2018

When I look at the SOA, it lists all of the Appendix A controls. My question is if the identified number of category 3 and 4 risks is low, then logically there will be a high number of SOA controls that do not apply and I would need to say “NO” in the Applicability column in the SOA table.

Answer: Your assumption is partially correct. If you have a low number of risks considered unacceptable, and that will require the implementation of security controls to be treated, then there is a great chance that for most controls in the SoA you will state them as non applicable. But you should note that controls may be required because of legal requirements (e.g., a law or contract), or because Top management decid ed for their implementation (by considering them as "good practice").

By the way, included in the toolkit you bought you have access to a video tutorial that can help you understand and fill the risk assessment and risk treatment templates.

This article will provide you further explanation about risk assessment and risk treatment:
- The basic logic of ISO 27001: How does information security work? https://advisera.com/27001academy/knowledgebase/the-basic-logic-of-iso-27001-how-does-information-security-work/

This material will also help you regarding risk assessment and risk treatment:
- Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
- The basics of risk assessment and treatment according to ISO 27001 [free webinar on demand] https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 21, 2018

Mar 21, 2018

Suggested Topics

Guest user Created:   May 27, 2018 ISO 27001 & 22301
Replies: 1
0 0

Risk assessment and SoA

Guest user Created:   Dec 23, 2021 ISO 27001 & 22301
Replies: 1
0 0

Risk assessment Vs SoA