SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Risk assessment approaches

  Quote
Guest
Guest user Created:   Jul 14, 2018 Last commented:   Jul 14, 2018

Risk assessment approaches

I would like to make request on three issue regarding ISO 27001:2013 implementation in building an ISMS
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jul 14, 2018

1- Which is the best approach to be used during risk assessment between Asset based and Processed approach?

Answer: First it is important to understand that ISO 27001 does not prescribe an approach to perform risk assessment, so you can choose the approach that better suits your needs.

Asset-based risk assessment is easier to perform, while the process-based risk assessment can provide you a more understandable context to identify and evaluate risks.

These materials will provide you further explanation about risk assessment approaches:
- ISO 27001 risk assessment: How to match assets, threats and vulnerabilities https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-how-to-match-assets-threats-and-vulnerabilities/
- ISO 31010: What to use instead of the asset-based approach for ISO 27001 risk identification https://advisera.com/27001academy/blog/2016/04/04/iso-31010-what-to-use-instead-of-the-asset-based-approach-for-iso-27001-risk-identification/
- Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/

2 - At what Stage do you determine residual risk and how best can it be done?

Answer: You determine residual risk after the definition of the risk treatment option and controls to be implemented (definition of the risk treatment plan).

These materials will provide you further explanation about residual risk:
- Why is residual risk so important? https://advisera.com/27001academy/knowledgebase/why-is-residual-risk-so-important/
- ISO 27001 risk assessment & treatment – 6 basic steps https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-treatment-6-basic-steps/
- The basics of risk assessment and treatment according to ISO 27001 [free webinar] https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 14, 2018

Jul 14, 2018

Suggested Topics

Guest user Created:   Oct 05, 2017 ISO 27001 & 22301
Replies: 1
0 0

Risk assessment approaches

Guest user Created:   Sep 10, 2020 ISO 27001 & 22301
Replies: 1
0 0

Risk Assessment

Guest user Created:   Aug 21, 2019 ISO 27001 & 22301
Replies: 1
0 0

Risk assessment approach