10.1 | Context of the organization | 2 |
10.2 | Leadership and commitment | 33 |
10.3 | Communication and consultation | 33 |
10.4 | Documented information | 27 |
10.4.2 | Documented information about processes | 26 |
10.4.3 | Documented information about results | 26 |
10.5 | Monitoring and review | 7 |
10.5.2 | Monitoring and reviewing factors influencing risks | 0 |
10.6 | Management review | 31 |
10.7 | Corrective action | 3 |
10.8 | Continual improvement | 34 |
3.1 | Terms related to information security risk | 0 |
3.2 | Terms related to information security risk management | 0 |
5.1 | Information security risk management process | 4 |
5.2 | Information security risk management cycles | 4 |
6.1 | Organizational considerations | 0 |
6.2 | Identifying basic requirements of interested parties | 0 |
6.3 | Applying risk assessment | 0 |
6.4 | Establishing and maintaining information security risk criteria | 1 |
6.4.2 | Risk acceptance criteria | 2 |
6.4.3 | Criteria for performing information security risk assessments | 0 |
6.5 | Choosing an appropriate method | 1 |
7.2 | Identifying information security risks | 0 |
7.2.1 | Identifying and describing information security risks | 0 |
7.2.2 | Identifying risk owners | 0 |
7.3 | Analysing information security risks | 1 |
7.3.2 | Assessing potential consequences | 1 |
7.3.3 | Assessing likelihood | 2 |
7.3.4 | Determining the levels of risk | 1 |
7.4 | Evaluating the information security risks | 0 |
7.4.1 | Comparing the results of risk analysis with the risk criteria | 0 |
7.4.2 | Prioritizing the analysed risks for risk treatment | 0 |
8.2 | Selecting appropriate information security risk treatment options | 0 |
8.3 | Determining all controls that are necessary to implement the information security risk treatment options | 0 |
8.4 | Comparing the controls determined with those in ISO/IEC 27001:2022, Annex A | 0 |
8.5 | Producing a Statement of Applicability | 0 |
8.6 | Information security risk treatment plan | 6 |
8.6.1 | Formulation of the risk treatment plan | 0 |
8.6.2 | Approval by risk owners | 0 |
8.6.3 | Acceptance of the residual information security risks | 0 |
9.1 | Performing information security risk assessment process | 0 |
9.2 | Performing information security risk treatment process | 0 |