ISO27001-2022-6.1.2
Evaluation Error: TypeError: Cannot read properties of undefined (reading 'file') at eval (eval at <anonymous> (plugin:dataview), <anonymous>:3:24) at DataviewInlineApi.eval (plugin:dataview:18885:16) at evalInContext (plugin:dataview:18886:7) at asyncEvalInContext (plugin:dataview:18896:32) at DataviewJSRenderer.render (plugin:dataview:18922:19) at DataviewJSRenderer.onload (plugin:dataview:18464:14) at DataviewJSRenderer.load (app://obsidian.md/app.js:1:1214378) at DataviewApi.executeJs (plugin:dataview:19465:18) at DataviewCompiler.eval (plugin:digitalgarden:10760:23) at Generator.next (<anonymous>)
Description
The organization shall define and apply an information security risk assessment process that:
a) establishes and maintains information security risk criteria that include:
-
- the risk acceptance criteria; and
-
- criteria for performing information security risk assessments;
b) ensures that repeated information security risk assessments produce consistent, valid and comparable results;
c) identifies the information security risks:
- criteria for performing information security risk assessments;
-
- apply the information security risk assessment process to identify risks associated with the loss of confidentiality, integrity and availability for information within the scope of the information security management system; and
-
- identify the risk owners;
d) analyses the information security risks:
- identify the risk owners;
-
- assess the potential consequences that would result if the risks identified in 6.1.2 c) 1) were to materialize;
-
- assess the realistic likelihood of the occurrence of the risks identified in 6.1.2 c) 1); and
-
- determine the levels of risk;
e) evaluates the information security risks:
- determine the levels of risk;
-
- compare the results of risk analysis with the risk criteria established in 6.1.2 a); and
-
- prioritize the analysed risks for risk treatment.
The organization shall retain documented information about the information security risk assessment process.