Expert Advice Community

Guest

Risk of identifying too few risks

  Quote
Guest
Guest user Created:   Jun 01, 2020 Last commented:   Jun 01, 2020

Risk of identifying too few risks

One quick question - is there any risk of our identifying too few risks that we think require treatment? Our risk assessment identifies around 200 scenarios (though we may decide that a large share of these are outside of our scope). For most of these, we have controls in place already and are willing to accept the residual risk. There are just a small handful where we think it would make sense to introduce additional controls. Is this something that an auditor would look askance at?

0 0

Assign topic to the user

ISO 27001 RISK ASSESSMENT AND TREATMENT REPORT

Document the results of the risk management process.

ISO 27001 RISK ASSESSMENT AND TREATMENT REPORT

Document the results of the risk management process.

Expert
Rhand Leal Jun 01, 2020

ISO 27001 does not require a "minimum" number of risks, only that relevant risks are identified and treated.

Considering that, the auditor will be more concerned about the quality of the identified risks (i.e., how relevant they are for the organizations) than their quantity. The single point you need to pay attention to is to not overlook obvious risks, i.e., risks that someone with proper competence to the process or asset would easily identify. To mitigate this risk you need to include in the risk assessment the personnel involved with the process or asset.

As for the number of risks (please note that the word "scenarios" is more adequate when talking about business continuity), you mentioned, 200 is a good number. To have a parameter, when using the asset-threat-vulnerability approach, a small organization generally identifies between 50 to 100 assets, with 3 vulnerabilities and 2 threats for each asset, so they identify between 300 to 600 risks.

An important thing to note is that risk for which you already have implemented controls (and you will only accept the risk) also count for your relevant risks.

These articles will provide you a further explanation about risk assessment and treatment:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Jun 01, 2020

Jun 01, 2020

Suggested Topics