ISO 28002:2011
Annex A: Planning – ISO 28002:2011

ISO 28002:2011 A.4.1: A.4.1 Risk assessment and monitoring

The organization sets up and keeps a risk assessment process that: identifies risks from intentional, unintentional and natural hazards and threats with direct or indirect effect on its activities, operations, functions, supply chain, human, intangible and physical assets, the natural environment and stakeholders; analyses risk systematically (likelihood, vulnerability, criticality of impact, consequences); picks out risks with significant effect on activities, functions, goods, services, supply chain, stakeholder relations and the environment; and evaluates and prioritises risk controls and treatment with their costs. It also: keeps this information documented, current and confidential where needed; reviews at set intervals the scope, the policy, the risk assessment and whether the context factors still hold; ensures priority risks shape the resilience system; reassesses when the context, operating environment, procedures, functions, services, partnerships or supply chain change; sets criteria for judging risk that reflect its values, objectives and resources; sets criteria for maximum acceptable downtime, recovery time objectives and acceptable loss for its goods, services, functions and supply chain; sets priority recovery times across the organization and the chain; and weighs the direct and indirect costs and benefits of risk reduction and resilience options. Annex B asks for a formal documented method to ISO 31000:2009 that covers threats, criticality, vulnerability, likelihood, consequence and impact analysis, dependencies in both directions along the chain, data and telecommunications integrity, and impact costs to people, finances, image, the community and the environment.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 4 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 22301:2019 · 2 controls

  • 8.2.2 Business impact analysis
  • 8.2.3 Risk assessment

ISO 28000:2022 · 2 controls

  • 6.1.2 Determining security-related risks and identifying opportunities
  • 8.3 Risk assessment and treatment

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Annex A: Planning – ISO 28002:2011

Query this from an agent

The graph holds this control, the 4 it maps to, and the evidence behind each claim, over MCP and REST.