SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Risk based calculation

  Quote
Guest
Guest user Created:   Jan 17, 2023 Last commented:   Jan 17, 2023

Risk based calculation

Why is risk only calculated based on Phycial Assets? What about best practices and processes and controls that are missing in an entity and causing risk?? Example HR practices, Asset practices. Does the CIA apply here?

Can I not calculate Risk along the same columns of controls defined in SOA and create another Risk assessment sheet for other Assets like Hardware mostly under CIA.

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Jan 17, 2023

ISO 27001 does not prescribe how to calculate risks, so organizations can adopt the approach that better suits their needs. 

Considering that, please note that the most commonly used approach is the asset-threat-vulnerability, which does not use only physical assets, but also, information, data, services, and other kinds of assets, where risks are determined according to their impacts related to information Confidentiality, Integrity, and Availability.

For further information, see:

In this article you will find information about:

  • Main steps in risk management
  • Risk assessment methodology
  • Risk assessment
  • What to use instead of an asset-based approach for ISO 27001 risk identification

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 17, 2023

Jan 17, 2023

Suggested Topics