Risk value calculation
Assign topic to the user
And if the risk value is calculated before considering existing controls, which risks should be moved to the risk treatment table? Is it only risks that are above the threshold value and do not have an existing control? Or any risk above the threshold value?
Answer: When defining the likelihood and impact values to calculate the risk you must consider any controls that are already implemented (and mention them in the column Existing controls at the end of the Risk Assessment Table).
Regarding which risks you should move to the Risk Treatment Table, you should move risks that are above the threshold value and any other risk you decide to treat (e.g., because you want to implement an improvement or you have to treat them because of a legal requirement).
By the way, included in the toolkit you bought you have access to a video tutorial that can help you fill the risk assessment and risk treatment tables.
Comment as guest or Sign in
Nov 28, 2017