Expert Advice Community

Guest

Risk owner

  Quote
Guest
Guest user Created:   Mar 18, 2020 Last commented:   Mar 18, 2020

Risk owner

1. I'm trying to find out who the risk owner would be for a technical risk (one of the nine from the STEEPCOIL)

2. With regards to the risk categories, do you know which one a power surge or a loss of power would fall under?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 18, 2020

1. I'm trying to find out who the risk owner would be for a technical risk (one of the nine from the STEEPCOIL)

I'm assuming that by STEEPCOIL you are referring to the acronym to Social, Technical, Economic, Environmental, Political, Commercial, Organizational, IT & Legal, used to grouping risks and opportunities.

Considering that, please note that ISO 27001 does not prescribes who the risk owner must be, so you can define any role you see fit. The concept adopted by ISO 27001 to risk owner is the one with the accountability and authority to manage a risk, i.e. the one who is both interested in resolving a risk, and with enough authority to do something about it.

For example, an asset owner of a server might be the IT administrator, and a risk owner for risks related to this server might be his boss, the head of the IT department.

For further information, see:

2. With regards to the risk categories, do you know which one a power surge or a loss of power would fall under?

Considering common definitions used for STEEPCOIL: the most adequate category for power surge and loss of power would be organizational risks because it covers risks related to structure and ownership assets responsible for the establishment and operation of a process facility (e.g., a power plant, or electricity company).

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 18, 2020

Mar 18, 2020