Expert Advice Community

Guest

Risk interviews and workshops

  Quote
Guest
Guest user Created:   Jul 16, 2016 Last commented:   Jul 16, 2016

Risk interviews and workshops

I have been reading the article on "risk assessment tips for smaller companies", again a very good article - very informative. In the article it refers to the risk assessment interview, do you have any examples of these interviews or scripts that could be used? Just to ensure we are asking the right questions and probing for the right information?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Dejan Kosutic Jul 16, 2016

Answer: These interviews are based on collecting all the information for the Risk assessment sheet - i.e. listing all the assets, vulnerabilities, threats, impact, likelihood, and risk owner. These materials will help you:
- article ISO 27001 risk assessment: How to match assets, threats and vulnerabilities https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-how-to-match-assets-threats-and-vulnerabilities/
- article How to assess consequences and likelihood in ISO 27001 risk analysis https://advisera.com/27001academy/iso-27001-risk-assessment-treatment-management/#assessment
- webinar The basics of risk assessment and treatment according to ISO 27 001 https://advisera.com/27001academy/webinar/basics-risk-assessment-treatment-according-iso-27001-free-webinar-demand/

The other question is related to the training awareness for risk assessment to asset and risk owners - is there any material you have which can give examples or demonstrate what we need to cover in the training.

Answer: You should organize a workshop and teach them how to perform the whole process themselves. The best would be to take one department as an example, and list all the assets/threats/vulnerabilities for that department, as well as related impacts/likelihoods - this is partially explained in my book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jul 16, 2016

Jul 16, 2016

Suggested Topics

Lajvar Created:   Apr 29, 2024 ISO 27001 & 22301
Replies: 1
0 0

Risk treatment plan

Tanya S Created:   Dec 01, 2023 ISO 27001 & 22301
Replies: 1
0 0

Residual Risk Calculations