O'Reilly logo

Information Security Risk Management for ISO27001/ISO27002 by Steve Watkins, Alan Calder

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

CHAPTER 13: RISK TREATMENT AND THE SELECTION OF CONTROLS

Once you have completed the risk assessment, you can move on to the selection of controls, and this chapter reviews the requirements of ISO27001 around control selection, which is also known as ‘risk treatment’.

As we said in Chapter 1, there are four risk treatment decisions that can be made:

•  accept the risk;

•  eliminate the risk by work-around or other arrangements;

•  control the risk to bring it to an acceptable level;

•  transfer it to a third party (e.g. via insurance).

The criterion that is used in making the decision is simple: either the risk is within the risk tolerance level, in which case it is accepted, or it is not, in which case it must be avoided, controlled or transferred. ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required