An introduction to information security

by The Open University

Available in 39 free installments

Owner:

View book

Email address:

Enter your email address above to start receiving your free daily installments.

Dripread will never disclose your email address to third parties.

5.2.4 Risk treatment

The risk treatment task is again carried out at unit level, in light of polices set out in Stages 1 to 3. The risks treated are those chosen for control at Stage 6.

Suitable controls are listed in Annexe A to Part 2 of the Standard, though this list is not exhaustive.

Documents drawn up in the risk treatment task should include evidence that each risk has been treated appropriately.

Figure 3View larger image Figure 3 The relationship between the stages and the tasks in the ISMS planning and documentation processLong description

Activity 13

In your own words, describe the tasks and stages of the ISMS planning and documentation process. Clearly identify the stages that are carried out at organisation level from those that are carried out at unit level within an organisation. Identify the information that flows between the tasks/stages.

Discussion

The activities of the ISMS documentation task are to define and record the context, scope and components of the ISMS. It comprises five stages:

These stages are all carried out at the organisation level.

The ISMS documentation task runs in parallel with the asset identification, risk assessment and risk treatment tasks, all of which are carried out at the level of individual organisational units.

In the asset identification task, the organisation's information assets, their owners, their locations, their values and their security requirements are established.

In the risk assessment task, the risks to those assets are determined, along with the potential costs of breaches of their security requirements. It consists of the following stages:

In the risk treatment task, suitable controls are selected to protect the information assets against loss or damage. It consists of a single stage:

The following information flows between the tasks/stages:

Original Copyright © 2007 The Open University. Now made available within the Creative Commons framework under the CC Attribution – Non-commercial licence (see http://creativecommons.org/by-nc-sa/2.0/uk/).