Expert Advice Community

Guest

Using risk assessment and treatment templates

  Quote
Guest
Guest user Created:   Dec 31, 2018 Last commented:   Jan 02, 2019

Using risk assessment and treatment templates

I have a question regarding the Risk Assessment and Treatment Documentation at the EU GDPR & ISO 27001 Integrated Documentation Toolkit; Do we have to create the following 3 documents Risk Assessment table, Risk Treatment Table and Risk assessment and treatment report as mentioned at the toolkit or we can use one sheet for the Assessment and treatment and reporting as the attached sheet?
0 0

Assign topic to the user

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

ISO 27001 DOCUMENTATION TOOLKIT

Step-by-step implementation for smaller companies.

Expert
Rhand Leal Dec 31, 2018

Answer:

Assuming that you are considering to be compliant with ISO 27001, then you have to document information related to the risk assessment and risk treatment processes. You can document this information in a single sheet, but we do not recommend this approach, because this way you will have a document that will be too big to be manageable and useful.

Quote
0 0
Guest
samarelshazly Jan 02, 2019

Fine , would you please clarify the aim from using the 07.3_Appendix_3_Risk_Assessment_and_Treatment_Report_Integrated_EN , i note that there is a redundancy of information at its contents from the methodology and risk assessment and risk treatment
though all the data regarding the risk assessment and risk treatment already mentioned at another documents with same names..so why using it ?

Quote
0 0
Expert
Rhand Leal Jan 04, 2019

Answer: Besides being one of the documents required for the certification audit, the Risk Assessment and Treatment Report is a summarized version of what is defined in the Risk Assessment and Treatment Methodology, as well as of the results of the risk assessment and treatment processes, to be presented to Top Management. With this report you can present only the relevant information for top management (for example, you do not need to include in the report all risks that were accepted according your risk acceptance criteria) and make the information easier to understand.

Quote
0 0

Comment as guest or Sign in

HTML tags are not allowed

Dec 31, 2018

Jan 04, 2019

Suggested Topics

Guest user Created:   Jun 12, 2020 ISO 27001 & 22301
Replies: 1
0 0

ISO 27001 scope

Guest user Created:   Mar 24, 2020 ISO 27001 & 22301
Replies: 3
0 1

Risk assessment