SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Risk owners and asset owners

  Quote
Guest
Guest user Created:   Aug 20, 2017 Last commented:   Aug 20, 2017

Risk owners and asset owners

Should we assign two different people to be the Risk Owner and Asset Owner or can they be just one person?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Aug 20, 2017

Answer: In fact, the two combinations are possible: these can be two separate persons, or one person can perform both roles, but you should note that while the asset owner is responsible for the protection and management of an asset, considering all risks related to that asset, the risk owner is accountable for, and has authority for managing a risk, considering all assets that can be associated to that risk, which are quite different things. So, before assigning a person to these both roles you should ensure he/she will not be overburdened by these activities.

This article will provide you further explanation about Risk owner and asset owner:
- Risk owners vs. asset owners in ISO 27001:2013 https://advisera.com/27001academy/knowledgebase/risk-owners-vs-asset-owners-in-iso-270012013/

These materials will also help you regarding Risk owner and asset owner:
- Book ISO 27001 Risk Management in Plain English https://advisera.com/books/iso-27001-annex-controls-plain-english/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Aug 20, 2017

Aug 20, 2017