Home About Gamma  Tour our Web Site  Events  White Papers  Services  Visitors' Book  How to contact us
         IMS  Internal Control  ISMS  Smart Cards  Common Criteria
                 

ISO/IEC 17799 and ISO/IEC27001 are predicated on risk assessment.  You cannot escape this - it is one of the working documents required for certification.  Moreover, the SOA is "based on the results and conclusions of the risk assessment and risk treatment process" and, thus, the risk assessment must be relevant to the SOA. It must also be relevant to your business, else the ISO/IEC 17799 controls that you adopt will not!  Not sure how to start... 

Your response - ask Gamma to help you perform your risk assessment

We will help you to perform your risk assessment and teach you how to do it at the same time, so that you can make the risk management decisions and maintain the risk assessment in the future.  We will also ensure that we identify the significant business risks, particularly those concerned with the business applications and not just the usual risks concerned with IT platforms and networks.  This is especially important from a corporate governance perspective. 

There are a variety of risk assessment tools that you can use (e.g. we have used CRAMM, Expert, RA and Riskwatch) but far far the best approach is the Brewer-List "Tell it like a story" method.  In this approach we start by identifying appropriate events. For each event (and we prefer to work with sets of events) we then:

  • identify your assets that may be affected
  • identify the threats that might cause the event
  • identify the vulnerabilities that might be exploited
  • identify the impacts that might then result
  • estimate the likelihood (or frequency) of the event as it occur under various event-circumstances (effectively these are subsets of events) and the severity of the resultant impact in the absence of any controls
  • exclude events which are then treated by avoiding the risk
  • exclude events which are deemed acceptable without mitigation by any control
  • determining the effect that existing controls (either controls that mitigate or transfer risk) have on modifying the likelihood (or frequency) of the impact and/or the severity of the impact
  • apply your risk acceptance criteria and thereby decide whether the residual risk is acceptable, or if not (or borderline) what action to take

Our results are presented in a Brewer-List Risk Treatment Plan. Note that this method does not only apply to information security. Use to it to determine all forms of risk: quality, business continuity, health and safety, financial, etc.

Your next move

Take a look at a page from our Template IMS to see an example (the Template IMS will open up in a new window. Please then navigate to the Risk Treatment Plan pages and select ES3) and then ...

... simply contact David Brewer. Why not do it now!

             
             
             
 
Gamma is an ISO/IEC 27001:2005 and BS EN ISO 9001: 2000 registered company, certified for the provision of information security consultancy.  BSI certificate numbers IS 85916 and FS  30710.  Please send comments to webmaster@gammassl.co.uk or complete our Visitors'Book. Gamma Secure Systems, Diamond House, Frimley Road, Camberley, Surrey, GU15 2PS, UK Tel: +44 1276 702500 - Fax: +44 1276 692903Copyright © Gamma Secure Systems Limited 1998-2006
 
 
Page last updated: 16 March, 2008