The Pros And Cons Of Risk Assessment

Improved Essays
The policy does not exist. However the risk assessment identified many risk that need to be addressed. Therefore, a policy is needed to address the risk found.

On page 7 of the Risk Assessment it was stated that SHGTS has never had a Risk Assessment before. This means that there was no policy in place to address the need for one.

Section 4.1 of ISO 27002:2005 says that risk assessment needs to be done periodically in a methodological manner (ISO/IEC 27002, 2005).

Since the policy does not exist, then the acceptable risk posture of the organization does not exist in such policy either.

The risk assessment discusses different levels of risk in the findings section on page 19. However acceptable risk was not determined.

Section 4.2 of
…show more content…
Section 4.1 of ISO 27002:2005 Recommends that risk assessment should be done periodically to identify and choose a correct way to handle it. This justified that it should be included in the policy (ISO/IEC 27002, 2005).

Since a policy does not exist, therefore a section on multi-perspectives also does not exist. However, a policy is needed to address the concerns in the risk assessment.

These concerns are listed in the Threat sources and Threat action section of the risk assessment on pages seventeen and eighteen. While Vulnerability space on assets and their impact can be seen on pages nineteen to twenty four. This section has valuable information to help in creating a needed policy.

As justification, I will make reference to the ISO 27002:2005 which in section 4.1 recommend multi-perspectives on risk be included in the ISMS. These perspectives includes Threat, Asset, Vulnerability and impact (ISO/IEC 27002, 2005) .

Since this policy does not exist, then there is no policy for include reporting results
…show more content…
This justifies that the results of the risk

Assessment should be included in the report (ISO/IEC 27002, 2005). Since this policy does not exist, then no section would have existed to include a remediation analysis report.

The risk assessment does not specifically mention the need for a remediation report in the policy. However, there are many recommendations that would aid in creating a report.

Section 14.1.2 of ISO 27002:2005 recommends that a strategy be put in place to address the threats posed by elements of the risk assessment. For this to happen, a remediation analysis report must be included in the policy. Without it this process will be overlooked (ISO/IEC 27002, 2005).

Procedures A procedure does not exist about implementing and enforcing a risk management policy. However the risk management assessment lacking this to help to address the risks identified.

On page 7 of the Risk Assessment stated that this is the first Risk Assessment done. This means that a procedure has not been implemented to enforce risk

Related Documents

  • Improved Essays

    Eighth, specific leadership issue is the organization does not address or hold public forums to gauge homeland security concerns with current and future products, services, and operations.(Fisher,2013). The first specific strategic planning issue is the organization may not have any strategic plans in place for homeland security, and this type of issue hurts the organization overall structure for homeland security. The second specific strategic planning issue is that there is not a vision in place that shows specific strategic objectives to executed a plan for homeland security issues in this organization. The third specific strategic planning issue is there are some key factors not being considered in homeland security strategic plan like a problem in its corporate intranet system or a problem with transportation. The fourth specific strategic planning issue is problems with transportation can mess with shipping and receiving goods and services and hurt supply chain needs.…

    • 842 Words
    • 4 Pages
    Improved Essays
  • Decent Essays

    FMECA Case Study

    • 2448 Words
    • 10 Pages

    Therefore, FMECA should be used in conjunction with other analytical tools when developing reliability estimates. [16] 1.2.7 Limitations of FMECA 1. Critical failure modes, causes, or effects that are not recognized by the designer(s) will not be addressed by the FMECA. 2. FMECA does not account for multiple-failure interactions, meaning that each failure is considered individually and the effect of several failures is not accounted for.…

    • 2448 Words
    • 10 Pages
    Decent Essays
  • Great Essays

    As the final appeal for the project (Geever, 2001), this proposal failed to move the funder further. Conclusion Technically speaking, the proposal did not mention how the leadership skill could be built by attaining those attributes, i.e. there is no definition of ‘Leadership’. In short, the proposal was detailed and informative that could give a clear picture to the reader. However, the planner failed to organise the useful materials to present to the potential funders.…

    • 1856 Words
    • 8 Pages
    Great Essays
  • Improved Essays

    Therefore, the contract had only reached the stage of offer and the offer did not make it up to the stage of acceptance. In consideration with this fact it can be stated that there had not been any legal agreement; hence, there is no legal contract between Robert and…

    • 1567 Words
    • 7 Pages
    Improved Essays
  • Improved Essays

    Hlg Case

    • 1334 Words
    • 6 Pages

    The applications of Ben and Connie have not conformed the current offer. There are no existences of building binding contracts. The HLG do not have the obliged to offer to discounts membership for…

    • 1334 Words
    • 6 Pages
    Improved Essays
  • Superior Essays

    Summary of Interface problems discovered First of all, at the beginning of each scenario, we were not provided with the task description. As a result, we had no choice but to “blindly” follow the steps in the scenario. In addition, since we did not have a clear goal in mind for every task, we were not able to answer most of the questions until we have “completed” one walkthrough. The scenarios themselves also lack certain details. For example, in the login step, username and password were not specified in the scenario.…

    • 1479 Words
    • 6 Pages
    Superior Essays
  • Improved Essays

    It also questions the future of R2P: if it is not being used to protect in a case when it should be used, will it be used at all in the future? This evidence determines that R2P is not an established norm, which weakens its impact. In other words, R2P is not used in all situations it could be used in and remains uncertain from a normative point of view. Furthermore, R2P was created to prevent the inconsistent humanitarian intervention of the 1990s, yet R2P is itself inconsistent and has often failed to…

    • 1304 Words
    • 6 Pages
    Improved Essays
  • Superior Essays

    1. The Employment Tribunal. 2. Nadine Quashie was not an employee and in any event did not have the requisite period of continuous employment. 3.…

    • 1192 Words
    • 5 Pages
    Superior Essays
  • Improved Essays

    Wrongful Removal We the Plaintiffs did, not file any amended pleadings or causes of actions claiming TILA. The Defendants did not file our motion with their removal. They claimed the motion…

    • 1647 Words
    • 7 Pages
    Improved Essays
  • Improved Essays

    Seeing as a multiverse is not something that can be observed, it can therefore not be measured or tested, and that means it should be placed under scrutiny. For example: in Vilenkin’s paper, these island universes our past our horizon of observation, which means that for all intense and purposes cannot ever be observed and only be speculated upon. Most of the hypotheses for a multiverse are formed from logical steps within other hypotheses that have data to back them up. There is no actual theory on the multiverse as there are interpretations stemming from current theories and hypotheses of our universe. There are even those that argue that some of the theories that the multiverse is based on could be wrong themselves.…

    • 2045 Words
    • 9 Pages
    Improved Essays