Expert Advice Community

Guest

Risk owner

  Quote
Guest
Guest user Created:   Oct 30, 2020 Last commented:   Oct 30, 2020

Risk owner

Assign ownership and accountabilities for strategic, aggregated, dynamic risks

0 0

Assign topic to the user

ISO 27001 RISK ASSESSMENT AND TREATMENT REPORT

Document the results of the risk management process.

ISO 27001 RISK ASSESSMENT AND TREATMENT REPORT

Document the results of the risk management process.

Expert
Rhand Leal Oct 30, 2020

Regardless of the type of risk, the risk owner should be someone with interest and authority to treat the risk.
 
Considering that, for strategic risks, the owner should be someone from top management.
 
By aggregated risks, I'm assuming you are referring to a set of related risks. In this case, the risk owner should be a role that can have the authority to treat all risks.
 
Regarding dynamic risks, the general rule about interest and authority applies.
 
This article will provide you a further explanation about risk owner:  

This material will also help you regarding Risk management:

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Oct 30, 2020

Oct 30, 2020