Questions tagged [iso27005]

ISO/IEC 27005:2011 provides guidelines for information security risk management. **source International Organization for Standardization** - [**ISO/IEC 27005:2011**][1] [1]: https://www.iso.org/standard/56742.html

ISO/IEC 27005:2011 is an international standard that provides guidance in establishing a risk management program, and describes how to implement each phase of risk management (identification, assessment, treatment, monitoring and review)

source Wikipedia:

2 questions
3
votes
2 answers

Is context establishment a repetitive process in standard ISO 27005?

I am writing our internal information security risk management procedure. This procedure should describe how exactly we do our risk identification, assessment, treatment and monitoring. I wanted to follow ISO 27005, but I am stuck in Context…
unixbek
  • 31
  • 2
-1
votes
1 answer

Potential risks per ISO 27002 clauses 5-18

I have a study project related to establishing of ISO 27001. I will do GAP analyses on "fictional" company over all ISO 27001 Annex A controls using ISO 27002. After I do that, I will detect the risks using the results of that GAP analyses. So my…
OrangeSpider
  • 31
  • 1
  • 4