Risk assessment approach
Assign topic to the user
Per this article ISO does not recommend asset based risk assessment, so why are you selling documentation based on old format.
Do you have any documentation based on new format?
Answer: Sorry, but I think there is a misunderstanding here
ISO 27001:2013 in fact does not require the use of an asset-threat-vulnerability approach for risk assessment anymore, but this does not mean that it is not recommended, only that organizations can adopt other approaches they consider are better suitable for them. They still can use the asset-threat-vulnerability approach if they want, and since this is still the most popular and the most optimal way to implement risk assessment we decided to keep it in our documentation.
Comment as guest or Sign in
Sep 05, 2019