SPRING DISCOUNT
Get 30% off on toolkits, course exams, and Conformio yearly plans.
Limited-time offer – ends April 25, 2024
Use promo code:
SPRING30

Expert Advice Community

Guest

Threat analysis

  Quote
Guest
Guest user Created:   Dec 14, 2016 Last commented:   Dec 14, 2016

Threat analysis

1 - How shall I treat the infrastructure such like the server room in our office? I am asking here because the server room itself does not threaten any information value. Is this asset supposed to be analyzed in the context of the server located there, then it would make sense to indicate for example pollution as threat. But wouldn’t it be redundant when you analysis the server itself and take pollution as threat again?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Dec 14, 2016

Answer: You are correct in your thinking that the server room should be analysed in the context of the server, and that threats which impact the server will also affect the server room (after all, the server room is a protection for the server), but you should note that impacts may be different for the server and the server room, resulting in different control measures. For example, pollution applied to a server affects only the server, while pollution applied to a server room affects all the servers in the room, as well as other equipment and assets inside the room (e.g., network devices, UPSs, etc.). To mitigate pollution i mpacts you may define a maintenance plan for both servers and server room, but the details of each plan will be completely different.

This article will provide you further explanation about threat analysis:
- ISO 27001 risk assessment: How to match assets, threats and vulnerabilities https://advisera.com/27001academy/knowledgebase/iso-27001-risk-assessment-how-to-match-assets-threats-and-vulnerabilities/

These materials will also help you regarding threat analysis:
- Book Secure & Simple: A Small-Business Guide to Implementing ISO 27001 On Your Own https://advisera.com/books/secure-and-simple-a-small-business-guide-to-implementing-iso-27001-on-your-own/
- Free online training ISO 27001 Foundations Course https://advisera.com/training/iso-27001-foundations-course/

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 14, 2016

Dec 14, 2016

Suggested Topics