Information security risk assessment
Summary
The organisation shall define and apply an information security risk assessment process to identify, analyse and evaluate risks.
risk assessmentcia triadrisk ownersrisk criteria
Read the full official text: https://www.iso.org/standard/27001
← Clause 600
A.6 People controls
Clause 613 →
Information security risk treatment & Statement of Applicability
Track ISO 27001 clause 612 as evidence
eurocompliant maps this obligation to a checklist task and the evidence that satisfies it, alongside every other framework you follow.
Start free trial