Expert Advice Community

Guest

Risk Treatment Plan and audit

  Quote
Guest
Guest user Created:   Sep 19, 2017 Last commented:   Sep 19, 2017

Risk Treatment Plan and audit

Should all the planned RTP be executed for Auditing or not?
0 0

Assign topic to the user

ISO 27001 RISK ASSESSMENT AND RISK TREATMENT METHODOLOGY

Define main rules for risk assessment and treatment.

ISO 27001 RISK ASSESSMENT AND RISK TREATMENT METHODOLOGY

Define main rules for risk assessment and treatment.

Expert
Rhand Leal Sep 19, 2017

Answer: I'm assuming that for RTP you are referring to Risk Treatment Plan. Considering that, the answer is no, you can leave some of the controls for the implementation for after the auditing under the following conditions:

1) That you have implemented before the audit the controls that mitigate the biggest risks – in other words, you can leave only less important controls for after the audit
2) That you have specified the deadlines for the controls that you will be implementing after the audit in your Risk Treatment Plan – of course, those deadlines must be after the audit date
3) That your risk owners or top management accept all the risks for which controls have not been implemented before the audit

This means that the most important controls must have ”implemented“ status at the audit, while the less important controls can have status ”planned“ or ”partially implemented" at the moment of the audit. Of course that for controls with status of ”partially implemented" you have t o keep evidences of activities already performed regarding the implementation (the auditor won't audit the control, but he will verify if the implementation plan is being executed).

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Sep 19, 2017

Sep 19, 2017

Suggested Topics

Ash Created:   Jan 21, 2024 ISO 27001 & 22301
Replies: 1
0 1

ISO 27001 Internal Audits

Guest user Created:   May 26, 2023 ISO 27001 & 22301
Replies: 1
0 0

Questions