How much Risk Assessment is needed?

In many of the InfoSec forums I subscribe to people regularly as  the “How long is a piece of string” question:

How extensive a risk assessment is required?

It’s a perfectly valid question we all have faced, along with the “where do I begin” class of questions.

The ISO-27001 standard lays down some necessities, such as your asset register, but it doesn’t tell you the detail necessary. You can choose to say “desktop PCs” as a class without addressing each one, or even addressing the different model. You can say “data centre” without having to enumerate every single component therein.

At first. Continue reading How much Risk Assessment is needed?