SlideShare a Scribd company logo
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
Phil Hare
Vigilant Software
Thursday May 30th
PLEASE NOTE THAT ALL DELEGATES IN THE TELECONFERENCE ARE MUTED ON JOINING.
Q&A IS HANDLED THROUGH THE GOTOWEBINAR QUESTION FUNCTION
Maintaining and updating your risk
assessment using vsRisk™
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
Phil Hare
• An information security professional with many years’ experience of
information security risk assessments.
• Heavily involved in the specification and creation of one of the
leading software tools for ISO 27001 compliant risk assessments
available today.
• A broad knowledge of the technical, procedural, methodological and
theoretical aspects of Information Security Risk Assessment.
• Instrumental in successful ISMS development projects across a
wide range of organisations.
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
Today’s Webinar in Context
• Today’s webinar is #4 in a series of 4 educational
webinars.
• The 4 webinars are designed to take you on a learning
journey:
• Webinar 1 - Why IS027001 for my Organisation?
• Webinar 2 – The Importance of risk management
• Webinar 3 – Carrying out a risk assessment using vsRisk
• Webinar 4 (Today) – Maintaining/updating your risk assessment
using vsRisk.
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
Today’s Agenda
• A short 20-30 minutes educational and informative talk:
• Quick recap of last 3 week’s webinar – Why ISO 27001, the
importance of risk management, and using vsRisk to carry out a
risk assessment.
• Why maintain and update your risk assessment?
• Maintaining and update your risk assessment using vsRisk -
software demonstration.
• Ample time for Q&A.
• Next steps including a special offer for vsRisk.
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
Recap – last 3 webinars
In the last 3 webinars we covered:
• What is information security?
• What is an information security management system (ISMS)?
• What is ISO 27001?
• Why should I and my organisation care about ISO 27001?
• The importance of risk management.
• Carrying out a risk assessment using vsRisk.
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
Why maintain/update your risk assessment?
Reason 1 – Required by ISO27001 (clause 4.2.3.d)
Review risk assessments at planned intervals and review the residual risks and the identified acceptable levels
of risks, taking into account changes to:
1. the organization;
2. technology;
3. business objectives and processes;
4. identified threats;
5. effectiveness of the implemented controls; and
6. external events, such as changes to the legal or regulatory environment, changed contractual obligations,
and changes in social climate.
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
Why review your risk assessment?
Reason 2 – Risks do actually change….
Any change to the environment within which the
Organisation operates will mean the ISMS should be
reviewed – e.g. change in risk environment, business
growth, change in legislation, change in supply chain…
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
Why review your risk assessment?
Management’s attitude to risk changes – which could reflect changes in
the funding cycle, the business environment, or in management!
The Organisation should review its risk acceptance criteria to confirm
that they still reflect the Management’s Risk Appetite
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
Why is vsRisk unique?
vsRisk is the only tool in its price range that integrates
out-of-the-box in to an ISO 27001 management system,
allowing users to carry out an automated, robust and
extensive cyber security risk assessment of their
organisation’s assets compliant with ISO 27001.
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
How does vsRisk help with review and
maintenance?
1. It’s a database – so it stores data exactly as created last time
around;
2. It has an automated process, which makes it very easy for a risk
review to produce results comparable to those achieved the last
time;
3. It’s easy to compare and contrast pre- and post- review states;
4. There’s even a built-in comment capability and an audit log
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
What does vsRisk already do for you?
Integrated, out-of-the-box, into an ISO 27001
management system – vsRisk employs a risk assessment
methodology that complies with ISO 27001 and ISO 27005,
reducing the risk of non-compliance at audit of an ISO
27001 ISMS.
Produced key ISO 27001 documentation – Statement of
Applicability and Risk Treatment Plan ensure consistency
in documentation quality and transparency across the risk
management process initially and over time.
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
vsRisk - Demo
Software demonstration – maintaining and updating a risk
assessment using vsRisk.
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
Next Steps – Special May offer of risk
assessment software vsRisk
• Purchases of vsRisk in May will include 1 years support and
upgrades for free (worth £150).
• To claim this offer, please visit www.vigilantsoftware.co.uk.
• Offer valid until Thursday May 31st.
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
Next Steps – Want to know more?
• If you would like to know more about ISO 27001,
including how to carry out an ISO 27001-compliant risk
assessment using vsRisk, please visit
http://www.vigilantsoftware.co.uk or email
servicecentre@vigilantsoftware.co.uk.
• Free trial of vsRisk available at
http://www.vigilantsoftware.co.uk
“Intelligent, simplified risk assessment”
Copyright © Vigilant Software Ltd 2013
Questions – we welcome them all!
Please type your questions into the Gotowebinar question
box – responses will be verbal and shared with all
delegates.

More Related Content

PPTX
Introducing vsRisk 2.6
PDF
Using vsRisk to carry out a risk assessment
PDF
Elastic Security: Enterprise Protection Built on the Elastic Stack
PDF
Elastic Security: Enterprise Protection Built on the Elastic Stack
PDF
Evident io Continuous Compliance - Mar 2017
PDF
Elastic Security: Enterprise Protection Built on the Elastic Stack
PDF
Developing a Rugged Dev Ops Approach to Cloud Security (Updated)
PDF
Elastic Security: Enterprise Protection Built on the Elastic Stack
Introducing vsRisk 2.6
Using vsRisk to carry out a risk assessment
Elastic Security: Enterprise Protection Built on the Elastic Stack
Elastic Security: Enterprise Protection Built on the Elastic Stack
Evident io Continuous Compliance - Mar 2017
Elastic Security: Enterprise Protection Built on the Elastic Stack
Developing a Rugged Dev Ops Approach to Cloud Security (Updated)
Elastic Security: Enterprise Protection Built on the Elastic Stack

What's hot (20)

PDF
The 7 Rules of IT Disaster Recovery by Acronis
PDF
Elastic Security: Protección empresarial basada en Elastic Stack
PDF
Matteo Meucci Isaca Venice - 2017
PPTX
Cyber Security testing in an agile environment
PDF
Don’t WannaCry? Here’s How to Stop Those Ransomware Blues
PDF
Open Source Security: How to Lay the Groundwork for a Secure Culture
PDF
DevOps Indonesia X Palo Alto and Dkatalis Roadshow to DevOpsDays Jakarta 2022
PDF
Elastic SIEM (Endpoint Security)
PDF
Acronis True Image 3rd Party Speed & Ransomware Tests, Apr 2017 from MRG Effitas
PDF
The Challenges of Scaling DevSecOps
PDF
Top 5 Data Security Strategies in QA
PPTX
Automating Open Source Security: A SANS Review of WhiteSource
PDF
Introduction to Azure Sentinel
PDF
Take Control: Design a Complete DevSecOps Program
DOCX
Top 5 reasons to purchase cisco asa 5500 series
PDF
Managing Traceability in an Agile, Safety-critical Development Environment
PDF
Top 10 Practices of Highly Successful DevOps Incident Management Teams
PPTX
DevSecOps
PDF
Ccna sec
PDF
Elastic Security: Proteção Empresarial construída sobre o Elastic Stack
The 7 Rules of IT Disaster Recovery by Acronis
Elastic Security: Protección empresarial basada en Elastic Stack
Matteo Meucci Isaca Venice - 2017
Cyber Security testing in an agile environment
Don’t WannaCry? Here’s How to Stop Those Ransomware Blues
Open Source Security: How to Lay the Groundwork for a Secure Culture
DevOps Indonesia X Palo Alto and Dkatalis Roadshow to DevOpsDays Jakarta 2022
Elastic SIEM (Endpoint Security)
Acronis True Image 3rd Party Speed & Ransomware Tests, Apr 2017 from MRG Effitas
The Challenges of Scaling DevSecOps
Top 5 Data Security Strategies in QA
Automating Open Source Security: A SANS Review of WhiteSource
Introduction to Azure Sentinel
Take Control: Design a Complete DevSecOps Program
Top 5 reasons to purchase cisco asa 5500 series
Managing Traceability in an Agile, Safety-critical Development Environment
Top 10 Practices of Highly Successful DevOps Incident Management Teams
DevSecOps
Ccna sec
Elastic Security: Proteção Empresarial construída sobre o Elastic Stack
Ad

Similar to Maintaining and updating your risk assessment using vsRisk (20)

PDF
Maintaining and updating your risk assessment using vsRisk
PDF
The importance of information security risk management
PDF
The Importance of Risk Management
PDF
Why ISO27001/ISO27005 for my organisation
PDF
Why ISO27001 For My Organisation
PPT
vsRisk - features and benefits.ppt
PDF
Neupart webinar 1: Four shortcuts to better risk assessments
PDF
How Does the New ISO 27001 Impact Your IT Risk Management Processes?
PDF
Neupart Bright Talk - How Does the New ISO 27001 Impact Your IT Risk Manageme...
 
PPT
ENTERPRISE risk management AWARENESS.ppt
PPTX
Introduction to Risk Management Fundamentals
PPTX
Risk Management - Jisc Digital Festival 2015
PDF
WEB APPLICATION FOR RISK ASSESSMENT WITH SECURITY FEATURES
PPT
Review of Enterprise Security Risk Management
DOCX
Chapter 1The International Information Systems Security Certifi.docx
PPT
Risk Management (1) (1).ppt
PDF
Risk Based Security Management
PDF
Iso 27001 2005- by netpeckers consulting
PPTX
Iso 27001 2013 clause 6 - planning - by Software development company in india
PDF
Information Security 20- Risk Assessment.pdf
Maintaining and updating your risk assessment using vsRisk
The importance of information security risk management
The Importance of Risk Management
Why ISO27001/ISO27005 for my organisation
Why ISO27001 For My Organisation
vsRisk - features and benefits.ppt
Neupart webinar 1: Four shortcuts to better risk assessments
How Does the New ISO 27001 Impact Your IT Risk Management Processes?
Neupart Bright Talk - How Does the New ISO 27001 Impact Your IT Risk Manageme...
 
ENTERPRISE risk management AWARENESS.ppt
Introduction to Risk Management Fundamentals
Risk Management - Jisc Digital Festival 2015
WEB APPLICATION FOR RISK ASSESSMENT WITH SECURITY FEATURES
Review of Enterprise Security Risk Management
Chapter 1The International Information Systems Security Certifi.docx
Risk Management (1) (1).ppt
Risk Based Security Management
Iso 27001 2005- by netpeckers consulting
Iso 27001 2013 clause 6 - planning - by Software development company in india
Information Security 20- Risk Assessment.pdf
Ad

Recently uploaded (20)

PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
MYSQL Presentation for SQL database connectivity
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
NewMind AI Monthly Chronicles - July 2025
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PPT
Teaching material agriculture food technology
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
PDF
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Advanced IT Governance
PDF
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
Per capita expenditure prediction using model stacking based on satellite ima...
Understanding_Digital_Forensics_Presentation.pptx
MYSQL Presentation for SQL database connectivity
The Rise and Fall of 3GPP – Time for a Sabbatical?
NewMind AI Monthly Chronicles - July 2025
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Teaching material agriculture food technology
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
20250228 LYD VKU AI Blended-Learning.pptx
Advanced methodologies resolving dimensionality complications for autism neur...
Review of recent advances in non-invasive hemoglobin estimation
[발표본] 너의 과제는 클라우드에 있어_KTDS_김동현_20250524.pdf
TokAI - TikTok AI Agent : The First AI Application That Analyzes 10,000+ Vira...
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Dropbox Q2 2025 Financial Results & Investor Presentation
Advanced IT Governance
solutions_manual_-_materials___processing_in_manufacturing__demargo_.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
“AI and Expert System Decision Support & Business Intelligence Systems”

Maintaining and updating your risk assessment using vsRisk

  • 1. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 Phil Hare Vigilant Software Thursday May 30th PLEASE NOTE THAT ALL DELEGATES IN THE TELECONFERENCE ARE MUTED ON JOINING. Q&A IS HANDLED THROUGH THE GOTOWEBINAR QUESTION FUNCTION Maintaining and updating your risk assessment using vsRisk™
  • 2. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 Phil Hare • An information security professional with many years’ experience of information security risk assessments. • Heavily involved in the specification and creation of one of the leading software tools for ISO 27001 compliant risk assessments available today. • A broad knowledge of the technical, procedural, methodological and theoretical aspects of Information Security Risk Assessment. • Instrumental in successful ISMS development projects across a wide range of organisations.
  • 3. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 Today’s Webinar in Context • Today’s webinar is #4 in a series of 4 educational webinars. • The 4 webinars are designed to take you on a learning journey: • Webinar 1 - Why IS027001 for my Organisation? • Webinar 2 – The Importance of risk management • Webinar 3 – Carrying out a risk assessment using vsRisk • Webinar 4 (Today) – Maintaining/updating your risk assessment using vsRisk.
  • 4. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 Today’s Agenda • A short 20-30 minutes educational and informative talk: • Quick recap of last 3 week’s webinar – Why ISO 27001, the importance of risk management, and using vsRisk to carry out a risk assessment. • Why maintain and update your risk assessment? • Maintaining and update your risk assessment using vsRisk - software demonstration. • Ample time for Q&A. • Next steps including a special offer for vsRisk.
  • 5. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 Recap – last 3 webinars In the last 3 webinars we covered: • What is information security? • What is an information security management system (ISMS)? • What is ISO 27001? • Why should I and my organisation care about ISO 27001? • The importance of risk management. • Carrying out a risk assessment using vsRisk.
  • 6. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 Why maintain/update your risk assessment? Reason 1 – Required by ISO27001 (clause 4.2.3.d) Review risk assessments at planned intervals and review the residual risks and the identified acceptable levels of risks, taking into account changes to: 1. the organization; 2. technology; 3. business objectives and processes; 4. identified threats; 5. effectiveness of the implemented controls; and 6. external events, such as changes to the legal or regulatory environment, changed contractual obligations, and changes in social climate.
  • 7. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 Why review your risk assessment? Reason 2 – Risks do actually change…. Any change to the environment within which the Organisation operates will mean the ISMS should be reviewed – e.g. change in risk environment, business growth, change in legislation, change in supply chain…
  • 8. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 Why review your risk assessment? Management’s attitude to risk changes – which could reflect changes in the funding cycle, the business environment, or in management! The Organisation should review its risk acceptance criteria to confirm that they still reflect the Management’s Risk Appetite
  • 9. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 Why is vsRisk unique? vsRisk is the only tool in its price range that integrates out-of-the-box in to an ISO 27001 management system, allowing users to carry out an automated, robust and extensive cyber security risk assessment of their organisation’s assets compliant with ISO 27001.
  • 10. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 How does vsRisk help with review and maintenance? 1. It’s a database – so it stores data exactly as created last time around; 2. It has an automated process, which makes it very easy for a risk review to produce results comparable to those achieved the last time; 3. It’s easy to compare and contrast pre- and post- review states; 4. There’s even a built-in comment capability and an audit log
  • 11. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 What does vsRisk already do for you? Integrated, out-of-the-box, into an ISO 27001 management system – vsRisk employs a risk assessment methodology that complies with ISO 27001 and ISO 27005, reducing the risk of non-compliance at audit of an ISO 27001 ISMS. Produced key ISO 27001 documentation – Statement of Applicability and Risk Treatment Plan ensure consistency in documentation quality and transparency across the risk management process initially and over time.
  • 12. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 vsRisk - Demo Software demonstration – maintaining and updating a risk assessment using vsRisk.
  • 13. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 Next Steps – Special May offer of risk assessment software vsRisk • Purchases of vsRisk in May will include 1 years support and upgrades for free (worth £150). • To claim this offer, please visit www.vigilantsoftware.co.uk. • Offer valid until Thursday May 31st.
  • 14. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 Next Steps – Want to know more? • If you would like to know more about ISO 27001, including how to carry out an ISO 27001-compliant risk assessment using vsRisk, please visit http://www.vigilantsoftware.co.uk or email servicecentre@vigilantsoftware.co.uk. • Free trial of vsRisk available at http://www.vigilantsoftware.co.uk
  • 15. “Intelligent, simplified risk assessment” Copyright © Vigilant Software Ltd 2013 Questions – we welcome them all! Please type your questions into the Gotowebinar question box – responses will be verbal and shared with all delegates.