6.0 Planning
6.1
Actions to address risk and
opportunities
When planning the Information
Security Management System the
organization shall consider the issues and requirements and determine the risk
and opportunities that need to be addressed to:
a)
Giving assurance that the Information Security
Management System can achieve its
intended use.
b)
Enhance desirable effects.
c)
Prevent or reduce , undesirable effects.
d)
Achieve improvement
The organization shall plan
to address these risk and opportunities.
The details for the Risk assessment are done as
per the Risk Management procedure ref. No.DOC XYZ issue no. 01 and the record
is maintained for the various areas in version
1.4.
User questions & answers