22As with ISO/IEC 27002, the key to selecting applicable controls is to undertake a comprehensive assessment of the organization’s information risks, which is one vital part of the ISMS. Furthermore,
management may elect to avoid, share or accept information risks rather than mitigate them through controls - a risk treatment decision within the risk management process.
Share with your friends: