SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Risk assessment and treatment

  Quote
Guest
Guest user Created:   Feb 18, 2020 Last commented:   Feb 19, 2020

Risk assessment and treatment

We had purchased Advisera’s ISO 27001/22301 documentation toolkit. With regard to the risk assessment and treatment score, our consultant wants to adopt a different matrix for preparing the risk register since he has not come across the scoring methodology you have suggested in the attached document.

Could you please confirm that the scoring method you have given us (for the likelihood, severity and risk scores) is an accepted method by certification bodies since we do not want to face problems with our certification body?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Feb 19, 2020

The Risk Assessment and Risk Treatment template is fully compliant with ISO 27001 requirements and is accepted by all certification bodies that have performed the audits on companies that use our toolkits.

However, please note that ISO 27001 does not prescribe how risk must be scored (only that consequence and likelihood must be assessed to determine risk), so if the approach used by your consultant fulfills the standards requirements it will also be acceptable by certification bodies. Please be aware that we offer the simplest method available, while consultants typically prefer more complex risk assessment methods.

This article will provide you a further explanation:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Feb 18, 2020

Feb 19, 2020