SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Risk assessment and treatment process

  Quote
Guest
Guest user Created:   Apr 28, 2018 Last commented:   Apr 28, 2018

Risk assessment and treatment process

I watched a PECB presentation on YouTube in which a presenter placed SoA as the last step in the risk management process. This contadicts with what you have written in your book.
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 28, 2018

Is the sequence in the last steps (SoA vs risk treatment plan) interchangeable or is there a correct way?

Answer: The ISO 27001 risk treatment consists of these requirements (exactly in this order):
- Selection of applicable risk treatment options
- Determination of necessary controls to implement the chosen options
- Comparison of determined controls against SO 27001 Annex A
- Elaboration of the Statement of Applicability
- Formulation of the Risk Treatment Plan
- Approval of the Risk Treatment Plan and residual risks

The standard follow this order because, besides the results of risk assessment, the risk treatment plan must also consider applicable legal requirements and top management decisions when defining actions, resources and deadlines to implement a control, and these information is found in the SoA justification for controls inclusions.

These articles will provide you further explanation about risk treatment and SoA:
- 4 mitigation options in risk treatment according to ISO 27001 https://advisera.com/27001academy/blog/2016/05/16/4-mitigation-options-risk-treatment-according-iso-27001/
- ISO 27001 risk assessment & treatment – 6 basic steps https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/
- Risk Treatment Plan and risk treatment process – What’s the difference? https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/#treatment
- The importance of Statement of Applicability for ISO 27001 https://advisera.com/27001academy/knowledgebase/the-importance-of-statement-of-applicability-for-iso-27001/

This material will also help you regarding risk treatment:
- The basics of risk assessment and treatment according to ISO 27001 [free webinar] https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Apr 28, 2018

Apr 28, 2018