Expert Advice Community

Guest

Risk management based on assets?

  Quote
Guest
Guest user Created:   Jan 13, 2016 Last commented:   Jan 13, 2016

Risk management based on assets?

0 0

Assign topic to the user

ISO 27001 INCIDENT MANAGEMENT PROCEDURE

The basics of detection and response to security incidents.

ISO 27001 INCIDENT MANAGEMENT PROCEDURE

The basics of detection and response to security incidents.

Guest
AntonioS Jan 13, 2016

Assets are usually used to perform the risk assessment – although not mandatory by ISO 27001:2013
How will i take risk assessment ? I mean based on what . Can I do implement ISo27001 with out asset management and risk assessment ?
 

Answer:

The recommendable is to have a risk management based on assets, although you are right, it is not mandatory. Another approach is to base your risk management in process, but generally it is for big companies. So, you can implement ISO 27001 without a risk management based on assets, although it is not recommendable (most of methodologies are based on assets). Anyway, the asset management is an important issue in ISO 27001, and you can do it independently of the risk management. Furthermore it is mandatory to have a document for the inventory of assets. 
You can see here the list of mandatory documents “List of mandatory documents required by ISO 27001 (2013 revision)” : https://advisera.com/27001academy/knowledgebase/list-of-mandatory-documents-required-by-iso-27001-2013-revision/
And this article can be also interesting for you “How to handle Asset register (Asset inventory) according to ISO 27001” : https://advisera.com/27001academy/knowledgebase/how-to-handle-asset-register-asset-inventory-according-to-iso-27001/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jan 13, 2016

Jan 13, 2016

Suggested Topics

Guest user Created:   Aug 21, 2019 ISO 27001 & 22301
Replies: 1
0 0

Risk assessment approach

Lajvar Created:   Apr 29, 2024 ISO 27001 & 22301
Replies: 0
0 0

Risk treatment plan