Risk management

Guest user Created:   Mar 12, 2018 Last commented:   Mar 12, 2018

Risk management

1- They ask for us to consider assets. Would a non-tangible assets such as intellectual property be considered an asset for ISO 27001.
Step-by-step implementation for smaller companies.


Step-by-step implementation for smaller companies.

Rhand Leal Mar 12, 2018

Answer: Non-tangible assets related to information or information processing facilities are also considered assets for ISO 27001. In fact, intellectual property usually is one critical information asset to be protected.

2- Is it possible to get a sample of a completed Appendix 1 – Risk Assessment table looks like?

Answer: Included in the toolkit you bought you have access to a video tutorial that can help you fill the risk assessment table, providing examples with real data.

3 - We are struggling with do we identify every single possible threat or just go with the most likely threats.

Answer: The identification of every single possible threat is unfeasible, so you have to focus on the most likely ones. To minimize chances that you miss a relevant threat, the risk identification step should count with the participation of personnel with knowledge about the situation being analysed (e.g., key users, systems administrators, etc.).

4 - Does the vulnerability relate to the threat or is it mutually exclusive in this table as in one has nothing to do with the other.

Answer: a vulnerability is weakness, associated to one or more assets, that can be exploited by one or more threat, so there is a relation between them.

5 - Can there be a 1 to many relationship of threat to vulnerability?

Answer: a single threat can explore many vulnerabilities, the same way a vulnerability can be exploited by many threats.

6 - Can an asset have many threats with many vulnerabilities?

Answer: A single asset can have many threat associated to it, and as explained in the previous answer, these threats can explore many vulnerabilities.

7 - Can a single threat or a single vulnerability have many controls?

Answer: Single threats / vulnerabilities can have multiple controls designated to handle them. In fact in many cases this is the most common situation (which we call "defense in depth", where multiple controls are implemented to ensure that if one fails some sort of security still remains, giving people more time to identify and react to the threat).

Mar 12, 2018

Mar 12, 2018