Who should access risk management documents
Assign topic to the user
Answer: When you perform the risk assessment, you should also assess the risks related to these ISMS documents - if the risks are high, then you should allow only a very few people to access them; if the risks are low, then you can allow a wider circle of people to access them.
This principle is called the classification of information - you can find more information in this article: https://advisera.com/27001academy/blog/2014/05/12/information-classification-according-to-iso-27001/
Comment as guest or Sign in
Aug 24, 2018

