Expert Advice Community

Guest

Risk management process

  Quote
Guest
Guest user Created:   Mar 26, 2020 Last commented:   Mar 26, 2020

Risk management process

Is the following order of steps for the risk management process provided in the iso27001 foundation course correct?
Shouldn't the RTP be created before the SoA?

1. Define risk assessment methodology
2. Conduct risk assessment
3. Select risk treatment options
4. Create Statement of Applicability (SoA)
5. Create risk treatment plan (RTP)

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 26, 2020

This order follows exactly the sequence of requirements of ISO 27001.

Please note that the Risk Treatment Plan defines the actions, resources, responsibilities, and dates for the implementation of risk treatment options (e.g., risk transfer and risk mitigation), and you first need these options to be approved, generally as part of the SoA approval, so you can minimize risks of rework or loss of time if a treatment option is not approved.

These articles will provide you further explanation about the risk management process:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 26, 2020

Mar 26, 2020

Suggested Topics