ISO 18788 - Clause 6.1.3 - Internal and External Risk Communication and Consultation
- Andy Systems
- SOMS Guides
ISO 18788 Clause 6.1.3 outlines the requirements for establishing a formal and documented communication and consultation process with both internal and external stakeholders during the risk assessment process within the Security Operations Management System (SOMS). This process ensures effective risk assessment and management by involving relevant parties. Here's an explanation of the key elements of this clause:
Clause 6.1.3 - Internal and External Risk Communication and Consultation:
-
Formal and Documented Process: The organization is required to establish, implement, and maintain a formal and documented communication and consultation process. This process is designed to facilitate effective interaction with internal and external stakeholders during the risk assessment process.
-
Understanding Operational Objectives and Client Interests: The process aims to ensure a clear understanding of operational objectives and the interests of the client. This includes comprehending the needs and expectations of the individuals, organizations, communities, or activities being protected by the security operations.
-
Adequate Risk Identification and Communication: The process ensures that risks are adequately identified and effectively communicated. This involves the comprehensive assessment and transparent sharing of risks.
-
Understanding Other Stakeholder Interests: The organization seeks to understand the interests of all relevant internal and external stakeholders beyond the client. This broader understanding is essential for addressing a wide range of concerns and perspectives.
-
Communication of Risks and Treatments: The process includes the communication of identified risks and the treatments or mitigation strategies associated with these risks. This sharing of information helps stakeholders make informed decisions.
-
Dependencies and Supply Chain Considerations: The process considers dependencies and linkages with subcontractors and throughout the supply chain. Understanding these relationships is critical for comprehensive risk assessment and management.
-
Integration with Other Management Disciplines: The organization ensures that the security operations risk assessment process interfaces effectively with other management disciplines within the organization. This integration ensures alignment with broader organizational goals and strategies.
-
Context and Parameters: The risk assessment process is conducted within the appropriate internal and external context and parameters relevant to the organization, its subcontractors, and the supply chain. This contextual understanding is vital for accurate risk assessment.
In summary, this clause underscores the importance of effective communication and consultation with stakeholders, both internal and external, throughout the risk assessment process. By involving relevant parties and considering a broad range of interests, the organization can enhance its risk assessment and management capabilities within the SOMS. The process should be formal, documented, and adaptable to the specific context and needs of the organization.