SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Risk assessment approach

  Quote
Guest
Guest user Created:   Sep 05, 2019 Last commented:   Sep 05, 2019

Risk assessment approach

Assign topic to the user

ISO 27001 RISK ASSESSMENT TABLE

Implement risk register using catalogues of vulnerabilities and threats.

ISO 27001 RISK ASSESSMENT TABLE

Implement risk register using catalogues of vulnerabilities and threats.

Expert
Rhand Leal Sep 05, 2019

Per this article ISO does not recommend asset based risk assessment, so why are you selling documentation based on old format.

Do you have any documentation based on new format?

Answer: Sorry, but I think there is a misunderstanding here

ISO 27001:2013 in fact does not require the use of an asset-threat-vulnerability approach for risk assessment anymore, but this does not mean that it is not recommended, only that organizations can adopt other approaches they consider are better suitable for them. They still can use the asset-threat-vulnerability approach if they want, and since this is still the most popular and the most optimal way to implement risk assessment we decided to keep it in our documentation.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Sep 05, 2019

Sep 05, 2019

Suggested Topics