Free ebook: NIS2 ready using ISO 27001 best practices
Download ebook

Assessment of the impact and likelihood of the risks and the scales used

Critical
High
Normal
Low

As part of the security risk assessment, the organization shall make assessments of the severity and probability of the risk materializing.

The organization shall have a clearly instructed risk scale that allows each participant in the risk assessment to decide on the appropriate level of severity and probability.

Connected other frameworks and requirements:
ID.RA-4: Impacts on business
NIST CSF

Follow-up analysis for security incidents

Critical
High
Normal
Low

If it is difficult to identify the source of a security incident based on the primary treatment, a separate follow-up analysis is performed for the incident, in which the root cause is sought to be identified.

Connected other frameworks and requirements:
16.1.6: Learning from information security incidents
ISO 27001
ID.RA-4: Impacts on business
NIST CSF
DE.DP-5: Detection processes improvment
NIST CSF
RS.AN-2: The impact of the incident
NIST CSF
RS.IM-1: Response plans
NIST CSF
No items found.