Expert Advice Community

Guest

Risk Treatment Table

  Quote
Guest
Guest user Created:   Apr 10, 2020 Last commented:   Apr 10, 2020

Risk Treatment Table

Should I include assessed ISMS Opportunities and Risks in the Risk Treatment Table? I mean IS Management System itself related Opportunities and risks?

0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Apr 10, 2020

Please note that ISO 27001 only requires documentation of risks related to information, not about risks and opportunities to the ISMS as a system. Therefore, you should not include them in the Risk Treatment Table, because the purpose of this table is to document the treatment of risks related to information and this can create confusion among users.

Quote
0 1

Comment as guest or Sign in

HTML tags are not allowed

Apr 10, 2020

Apr 10, 2020