You are on page 1of 1

KEY STEPS FOR ISO/IEC 27001 RISK ANALYSIS

Using ISO/IEC 27001 to assess and treat threats to our Information Assets.

IDENTIFY RISKS TREAT RISKS

THREATS ACCEPT RISK


INCIDENTS AVOID RISK
VULNERABILITIES TRANSFER RISK
ASSETS REDUCE RISK

STRATEGY ADAPT
CONTINUAL
RISK APPETITE
DEVELOPMENT

EVALUATE RISKS HANDLE CHANGES

You might also like