You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In the risk treatment plan, the word “reduction” should be changed to “modification.” (ISO 27005:8.2)
The algorithm of modification should be reviewed accordingly
Operational risk should be renamed, in the norm it is now referenced rather to the information risk (ISO 27005:A.13 (and a lot of others implicit references)), I propose to rename it to "strategic risk"
The tool has to evolve like the norm :
First phase changes:
** Bonus **
Second phase changes: