Replies: 1 comment
-
|
According to chapter 6.1, the addressing of opportunities is a requirement for ISO 27001. Therefore, I would consider this as an elemental function to be integrated. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Problem statement
I want to be able to record, evaluate, and track the realization of opportunities, but the current implementation only allows for risks.
Expected behavior
The existing risk management section could be reused or duplicated, with field names and values inverted.
Mock
Additional context
Ugh, I just noticed my mock-ups are messed up...
(1)
Risk assessment > Opportunity assessment
Associated risk scenarios > Associated opp. scenarios
+Add risk scenario > Add opp. scenario
Threats > Improvments
(2)
Risk matrix view > Opportunities evaluation
Likelihood > Effort
Impact > Value
(3)
Threats > Opportunities
Beta Was this translation helpful? Give feedback.
All reactions