Expert Advice Community

Guest

Risk treatment

  Quote
Guest
Guest user Created:   Mar 16, 2017 Last commented:   Mar 16, 2017

Risk treatment

1 - Regarding the Risk Assessment Table, Can I use '3rd party' as a Risk Owner in some cases?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Mar 16, 2017

Answer: No. Risk owners are persons from the organization that are responsible for the risks. What can happen is that the risk treatment can be transferred to a 3rd party, but the ultimate responsibility for the risk still is with the organization.

This article will provide you further explanation about risk treatment:
- 4 mitigation options in risk treatment according to ISO 27001 https://advisera.com/27001academy/blog/2016/05/16/4-mitigation-options-risk-treatment-according-iso-27001/

2 - And what about rules for interns?

Answer: The establishment of information security rules for interns must follow the local laws, regulations and other legal requirements applicable. On top of that, you can set any security rules for interns that reflect the risks related to their work.

This article will provide you further explanation about identification of requirements:
- How to identify ISMS requirements of interested parties in ISO 27001 https://advis era.com/27001academy/blog/2017/02/06/how-to-identify-isms-requirements-of-interested-parties-in-iso-27001/

Additionally, in the video tutorials that came with your toolkit, you can see examples of how to fill out all the data for Risk assessment and Risk treatment.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Mar 16, 2017

Mar 16, 2017

Suggested Topics

Gerry Created:   Sep 18, 2023 ISO 27001 & 22301
Replies: 2
0 0

Risk Treatment Advice

Guest user Created:   Nov 27, 2022 ISO 27001 & 22301
Replies: 1
0 0

Risk Treatment and RTP