Guest
Risk Treatment Table
Should I include assessed ISMS Opportunities and Risks in the Risk Treatment Table? I mean IS Management System itself related Opportunities and risks?
Assign topic to the user
Expert
Rhand Leal
Apr 10, 2020
Please note that ISO 27001 only requires documentation of risks related to information, not about risks and opportunities to the ISMS as a system. Therefore, you should not include them in the Risk Treatment Table, because the purpose of this table is to document the treatment of risks related to information and this can create confusion among users.
Comment as guest or Sign in
Apr 10, 2020
Apr 10, 2020
Apr 10, 2020